CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Other sources
Memory leak in code preparing DNSSEC proofs of non-existence
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.21 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.21.20 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.21-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3104?
CVE-2026-3104 has been classified with a severity rating of medium due to the potential for a memory leak when handling specific DNS queries.
How do I fix CVE-2026-3104?
To fix CVE-2026-3104, update your BIND 9 installation to version 9.20.21 or 9.21.20, which contain the necessary patches.
Which versions of BIND 9 are affected by CVE-2026-3104?
CVE-2026-3104 affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
What type of attack is possible with CVE-2026-3104?
The vulnerability allows an attacker to exploit a memory leak in the BIND resolver by querying a specially crafted domain.
What is the impact of CVE-2026-3104 on DNS services?
CVE-2026-3104 can lead to performance degradation and increased resource consumption on DNS services due to the memory leak.