Description
If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A BIND 9 resolver may abort with an unexpected program exit when it receives a DNSSEC-signed authoritative zone that replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC record at the same owner name. This flaw, identified as CWE‑617, results in a crash that can be exploited to deny service to the resolver.

Affected Systems

Affected products are ISC BIND 9. Vulnerable releases include 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, as well as the corresponding signed releases 9.11.3‑S1 to 9.18.50‑S1 and 9.20.9‑S1 to 9.20.27‑S1.

Risk and Exploitability

The CVSS score of 7.5 illustrates a high impact on availability, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog and no public exploits are known. Based on the description, it is inferred that an attacker can trigger the crash by serving crafted responses from a malicious authoritative server over the network, requiring control of zone data rather than privileged local access. No workarounds are known, so mitigation relies solely on applying the vendor patch.

Generated by OpenCVE AI on September 18, 2026 at 02:48 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade to BIND 9.20.29, 9.21.26, or 9.20.29‑S1.
  • Restart the BIND service so the new software takes effect.
  • Monitor BIND logs for crashes to confirm that the patch is effective.

Generated by OpenCVE AI on September 18, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Isc bind 9
Vendors & Products Isc bind 9

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Validating resolver can abort while caching a mismatched NOQNAME proof
First Time appeared Isc
Isc bind
Weaknesses CWE-617
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T17:37:27.082Z

Reserved: 2026-08-26T07:08:07.730Z

Link: CVE-2026-80274

cve-icon Vulnrichment

Updated: 2026-09-17T17:37:23.422Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:52.690

Modified: 2026-09-17T18:17:09.007

Link: CVE-2026-80274

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:07:20Z

Links: CVE-2026-80274 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses