CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path
On a resolver configured to use dns64, if an applicable answer from the authoritative server is malformed in a specific way, the resolver named process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BIND 9 (named) with dns64to a version that resolves this vulnerability.Fixed in 9.20.29 - Upgrade
Upgrade
BIND 9 (named) with dns64to a version that resolves this vulnerability.Fixed in 9.21.26 - Upgrade
Upgrade
BIND 9 (named) with dns64to a version that resolves this vulnerability.Fixed in 9.20.29-S1
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Affected deployments are BIND 9 resolvers running an affected version and configured to use dns64. The vulnerable ranges are 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
What does an attacker need to trigger the failure?
An attacker needs an applicable DNS answer from an authoritative server that is malformed in a specific way. No privileges or user interaction are required according to the supplied severity vector.
What is the practical impact of successful exploitation?
Successful exploitation causes the resolver's named process to exit unexpectedly, resulting in a denial of service. The supplied vector indicates no confidentiality or integrity impact.