Description
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch Now
AI Analysis

Impact

The flaw occurs when a BIND resolver processes an SVCB/HTTPS AliasMode record that references fourteen or more SVCB/HTTPS ServiceMode records. The resolver fails to release internal memory and a reference cache, causing a memory leak that can grow with repeated lookups. Over time the resolver runs out of available resources, any new recursive lookup attempts fail, and DNS service becomes unavailable for clients.

Affected Systems

The vulnerability impacts ISC BIND 9 in several released branches. Affected versions include 9.18.0 to 9.18.50, 9.20.0 to 9.20.27, 9.21.0 to 9.21.25, the 9.18.11-S1 through 9.18.50-S1 maintenance updates, and the 9.20.9-S1 through 9.20.27-S1 S1 releases. Systems running these binaries should verify their current release against the patched versions 9.20.29, 9.21.26, or 9.20.29‑S1.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating high overall risk. The EPSS score is below 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the condition by sending crafted DNS responses or by manipulating zone data that forces the resolver to retrieve many ServiceMode records. Based on the description, it is also inferred that the attack path is remote, as the resolver accepts DNS traffic from the network. The combination of high impact and low exploitation likelihood places the threat at moderate risk for environments that expose recursive resolution to potentially untrusted queries.

Generated by OpenCVE AI on September 18, 2026 at 03:50 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade ISC BIND 9 to the patched releases 9.20.29, 9.21.26, or 9.20.29‑S1
  • Restrict recursive queries to trusted networks to reduce exposure to untrusted traffic
  • Monitor DNS traffic and resource usage for signs of exhaustion after the patch

Generated by OpenCVE AI on September 18, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Isc bind 9
Vendors & Products Isc bind 9

Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title SVCB AliasMode additional-data error leaks qpcache references
First Time appeared Isc
Isc bind
Weaknesses CWE-401
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T17:47:23.137Z

Reserved: 2026-08-27T05:57:37.544Z

Link: CVE-2026-81563

cve-icon Vulnrichment

Updated: 2026-09-17T17:47:18.275Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:10.543

Modified: 2026-09-17T18:17:09.147

Link: CVE-2026-81563

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:00:04Z

Links: CVE-2026-81563 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-772

    Missing Release of Resource after Effective Lifetime