Search CVE reports


Toggle filters

21 – 30 of 91 results


CVE-2026-11605

Medium priority
Fixed

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Not affected Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected Not affected Not affected
bind9-libs Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-11331

Medium priority

Some fixes available 3 of 12

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-10822

Medium priority

Some fixes available 3 of 12

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-10723

Medium priority

Some fixes available 3 of 12

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-5950

Medium priority

Some fixes available 4 of 10

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Not affected Not affected
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-5947

Medium priority
Fixed

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the...

3 affected packages

bind9-libs, bind9, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9-libs Not in release Not in release Not affected Not affected
bind9 Fixed Not affected Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-5946

Medium priority

Some fixes available 6 of 8

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the...

3 affected packages

bind9, bind9-libs, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Fixed Fixed
bind9-libs Not in release Not in release Vulnerable Vulnerable
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-3593

Medium priority
Fixed

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through...

3 affected packages

bind9-libs, bind9, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9-libs Not in release Not in release Not affected Not affected
bind9 Fixed Not affected Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-3592

Medium priority

Some fixes available 6 of 12

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Fixed Fixed
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-3039

Medium priority

Some fixes available 8 of 10

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be...

3 affected packages

bind9, bind9-libs, isc-dhcp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Fixed Fixed
bind9-libs Not in release Not in release Vulnerable Vulnerable
isc-dhcp Not affected Not affected Not affected Not affected Not affected
Show less packages