Description
A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

A BIND recursive resolver can consume excessive CPU and memory when it receives many invalid DNSSEC records that match a specific pattern. The flaw is a resource management weakness (CWE-407) that is amplified by improper memory allocation (CWE-770). If exploited, the resolver may become unresponsive because the system runs out of space or processing power to handle legitimate queries.

Affected Systems

ISC BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, the corresponding -S1 releases, and 9.20.9-S1 through 9.20.27-S1 are affected. Any environment running these releases is at risk if it operates as a recursive resolver.

Risk and Exploitability

The likely attack vector is sending crafted DNS responses that contain many invalid DNSSEC records to the resolver. The CVSS score of 5.3 indicates a moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, widespread exploitation is currently unlikely, but the attack surface exists because the vulnerability is triggered by ordinary DNS traffic routed to the server. An attacker can send crafted DNS responses that contain a large number of invalid DNSSEC records; if the resolver processes them, the local resources may be exhausted, leading to a denial-of-service of the DNS service. The vulnerability is most likely exploitable over the network by any party that can manipulate upstream responses or control DNS traffic destined for the server.

Generated by OpenCVE AI on September 18, 2026 at 02:30 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade the BIND installation to a patched release—9.20.29, 9.21.26, or 9.20.29-S1—provided by ISC.
  • Configure network filtering or ACLs to block or rate-limit responses that contain anomalous DNSSEC records, thereby reducing exposure to excessive material matching.
  • Monitor DNS query rates, memory, and CPU usage for sudden spikes and configure automated alerts or service restarts to mitigate any DoS impact that may arise before the patch is deployed.

Generated by OpenCVE AI on September 18, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching
First Time appeared Isc
Isc bind
Weaknesses CWE-407
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:40:52.996Z

Reserved: 2026-08-12T20:32:58.421Z

Link: CVE-2026-19668

cve-icon Vulnrichment

Updated: 2026-09-17T18:40:47.755Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:33.633

Modified: 2026-09-17T19:16:42.057

Link: CVE-2026-19668

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T14:12:34Z

Links: CVE-2026-19668 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity

  • CWE-770

    Allocation of Resources Without Limits or Throttling