Description
If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via crash of named
Action: Immediate Patch
AI Analysis

Impact

A flaw in the dns_ncache_add function of ISC BIND 9 arises when an authoritative server returns a negative answer that is exactly 65536 bytes. The 16-bit length field in the cache entry is truncated, creating a cache entry of size zero but recorded as negative. When this corrupt entry is later read, the named daemon aborts. The result is a denial of service that disrupts name resolution services.

Affected Systems

The vulnerability affects ISC BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, as well as the corresponding -S1 branch releases (9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1). Operators running any of these revisions on authoritative, stub, or recursive name servers are potentially impacted, especially if they depend on upstream authoritative servers that could be controlled by an adversary.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, but the EPSS score of less than 1% signals that large-scale exploitation is currently uncommon. The vulnerability is not listed in CISA’s KEV catalog, further reflecting a low probability of targeted attacks. Exploitation requires an attacker to control an authoritative server or otherwise deliver a crafted negative DNS response; thus the attack vector is remote and would typically involve spoofing or poisoning a DNS path to influence the resolver in danger. Because the denial of service manifests as a crash in the named process, the impact is limited to availability, but repeated crashes could lead to a broader outage of DNS resolution services.

Generated by OpenCVE AI on September 18, 2026 at 00:19 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade ISC BIND 9 to a patched release, such as 9.20.29, 9.21.26, or 9.20.29-S1, following the vendor’s release notes.
  • Restart the named daemon after the upgrade to ensure the new binaries are in use.
  • Temporarily restrict outbound DNS traffic from authoritative servers that might generate large negative responses, or isolate critical resolvers behind redundant instances to mitigate accidental service disruption.

Generated by OpenCVE AI on September 18, 2026 at 00:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Isc bind 9
Vendors & Products Isc bind 9

Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`
First Time appeared Isc
Isc bind
Weaknesses CWE-197
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:45:36.926Z

Reserved: 2026-08-12T20:29:23.400Z

Link: CVE-2026-19667

cve-icon Vulnrichment

Updated: 2026-09-17T18:45:31.655Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:05.037

Modified: 2026-09-17T19:16:41.913

Link: CVE-2026-19667

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T13:46:56Z

Links: CVE-2026-19667 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-197

    Numeric Truncation Error