CVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/bind9to a version that resolves this vulnerability.Fixed in 1:9.16.50-1~deb11u2Fixed in 1:9.16.50-1~deb11u6Fixed in 1:9.18.49-1~deb12u2Fixed in 1:9.20.26-1~deb13u1Fixed in 1:9.20.26-1Fixed in 1:9.20.27-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.21.24 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.26-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10822?
The severity of CVE-2026-10822 is classified as medium, with a CVSS score of 6.5.
How do I fix CVE-2026-10822?
To fix CVE-2026-10822, update your ISC BIND software to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-10822?
CVE-2026-10822 may cause BIND to abort and exit unexpectedly when processing certain invalid DNS records.
Which versions of ISC BIND are affected by CVE-2026-10822?
ISC BIND versions prior to the fixed releases announced after July 22, 2026, are vulnerable to CVE-2026-10822.
What conditions lead to CVE-2026-10822 being exploited?
CVE-2026-10822 can be exploited if BIND stores a DNS record for a key that specifies a PRIVATEDNS algorithm and encounters an invalid data structure.