CVE-2026-19667: Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`

Published Sep 16, 2026
·
Updated

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in named results in a negative cache entry of 0 bytes. When this entry is subsequently read, named aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

Affected Software

1 affected component
ISC BIND 9>=9.11.0<=9.18.50, >=9.20.0<=9.20.27, >=9.21.0<=9.21.25, >=9.11.3-S1<=9.18.50-S1, >=9.20.9-S1<=9.20.27-S1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade BIND 9 (named) to a version that resolves this vulnerability.

    Fixed in 9.20.29
  2. Upgrade

    Upgrade BIND 9 (named) to a version that resolves this vulnerability.

    Fixed in 9.21.26
  3. Upgrade

    Upgrade BIND 9 (named) to a version that resolves this vulnerability.

    Fixed in 9.20.29-S1

Event History

Sep 16, 2026
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments running named in the affected ISC BIND 9 version ranges are exposed if they can query an attacker-controlled authoritative server that returns the required negative response. The issue is remotely reachable and requires no privileges or user interaction.

2

What must an attacker do to trigger the crash?

An attacker needs to operate or control an authoritative DNS server and return a negative answer whose size is exactly 65,536 bytes. This causes named to store a zero-byte negative cache entry; named aborts when that cached entry is later read.

3

Is the impact limited to a single failed DNS query?

No. The malformed negative response is placed in the negative cache, and the abort occurs when the resulting cache entry is subsequently read. The stated impact is denial of service, with no confidentiality or integrity impact indicated.

4

How can I determine whether an instance is affected?

Check the installed BIND 9 version against the affected ranges: 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, or 9.20.9-S1 through 9.20.27-S1. The available reference releases include 9.20.29 and 9.21.26.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203