Description
In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory exhaustion and potential denial of service
Action: Apply patch
AI Analysis

Impact

An attacker can craft DNS responses containing multiple identical singleton RDATA records, such as duplicate SOA records. When these duplicates are processed by the resolver, the record is appended to the in-memory RDATA set, increasing memory consumption in the negative cache. This can lead to excessive memory usage and potential denial of service if the attacker repeats the action.

Affected Systems

ISC BIND 9 implementations from version 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and the corresponding security‑patched releases 9.11.3‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.27‑S1. Any system running these versions of ISC BIND 9 on any platform is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires network access to the named service and the ability to send crafted responses; an attacker could trigger repeated cache growth leading to memory exhaustion, potentially disrupting DNS service availability.

Generated by OpenCVE AI on September 18, 2026 at 02:29 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade ISC BIND 9 to the patched release most closely aligned with your current version: 9.20.29, 9.21.26, or 9.20.29‑S1.
  • If an upgrade is not immediately possible, restrict DNS query sources to trusted networks or apply rate limiting to reduce the volume of incoming responses that could trigger cache growth.
  • Monitor the negative cache size and overall memory usage on DNS servers, and set appropriate limits or thresholds to detect abnormal growth patterns that may indicate an ongoing attack.

Generated by OpenCVE AI on September 18, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Message parser retains every identical singleton RDATA, enabling wire-to-work amplification
First Time appeared Isc
Isc bind
Weaknesses CWE-405
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:40:16.774Z

Reserved: 2026-08-17T14:56:23.749Z

Link: CVE-2026-75029

cve-icon Vulnrichment

Updated: 2026-09-17T18:40:10.774Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:43.577

Modified: 2026-09-17T19:16:58.037

Link: CVE-2026-75029

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T14:15:12Z

Links: CVE-2026-75029 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-405

    Asymmetric Resource Consumption (Amplification)

  • CWE-770

    Allocation of Resources Without Limits or Throttling