CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Other sources
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see:
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.16.50-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.21-1 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.18.47 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.21 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.21.20 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.18.47-S1 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.21-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1519?
CVE-2026-1519 is rated as high severity due to the potential for excessive CPU load during DNSSEC validation.
How do I fix CVE-2026-1519?
To mitigate CVE-2026-1519, upgrade to the latest version of BIND that addresses this vulnerability.
What versions of BIND are affected by CVE-2026-1519?
CVE-2026-1519 affects BIND versions from 9.11.0 to 9.16.50 and from 9.18.0 to 9.18.46, among others.
What type of servers are vulnerable to CVE-2026-1519?
BIND resolvers performing DNSSEC validation are vulnerable to CVE-2026-1519, while authoritative-only servers are generally unaffected.
What issue does CVE-2026-1519 highlight?
CVE-2026-1519 highlights a problem where excessive NSEC3 iterations can lead to high CPU load during insecure delegation validation.