Description
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit.
This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

If a BIND instance loads a configuration file without the required global options block, a malicious TKEY query may trigger an assertion failure that brings the server to an unexpected exit. This results in a denial‑of‑service condition and may cause the DNS service to become unavailable to clients. The weakness is reflected in CWE‑617.

Affected Systems

The flaw affects all BIND 9 releases from 9.20.0 through 9.20.27, from 9.21.0 through 9.21.25, and from the short‑lived 9.20.9‑S1 through 9.20.27‑S1. All installations that use ISC BIND 9 and rely on the default named.conf configuration without an options stanza are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate to high severity, while the EPSS of less than 1 % signals a very low but non‑zero likelihood of exploitation in the wild; the vulnerability is currently not listed in CISA’s KEV catalog. An attacker simply needs to send a crafted TKEY query to the exposed BIND server; no privileged access or complex setup is required. Because the problem is triggered by a missing configuration element, it can be rendered inoperable with a relatively simple patch or configuration change.

Generated by OpenCVE AI on September 18, 2026 at 02:33 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Apply the ISC‑recommended upgrade to BIND 9.20.29, 9.21.26, or 9.20.29‑S1.
  • Ensure that a global "options" block is present in the named.conf file used by the server.
  • Restart the BIND service after applying the patch or configuration change to bring the updated configuration into effect.

Generated by OpenCVE AI on September 18, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Isc bind 9
Vendors & Products Isc bind 9

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
Title named aborts on a TKEY query when the user configuration has no global options statement
First Time appeared Isc
Isc bind
Weaknesses CWE-617
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T17:38:11.268Z

Reserved: 2026-08-19T08:52:01.762Z

Link: CVE-2026-76163

cve-icon Vulnrichment

Updated: 2026-09-17T17:37:49.484Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:43.847

Modified: 2026-09-17T18:17:08.720

Link: CVE-2026-76163

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:05:34Z

Links: CVE-2026-76163 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses