CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
Other sources
A use-after-return vulnerability exists in the named server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
— NVD
Affected Software
Remediation
Information
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3591?
CVE-2026-3591 has a high severity rating due to the potential for ACL bypass through a stack use-after-return vulnerability.
How do I fix CVE-2026-3591?
To fix CVE-2026-3591, upgrade your ISC BIND 9 software to version 9.20.21 or 9.21.20 or later.
What versions of ISC BIND 9 are affected by CVE-2026-3591?
ISC BIND 9 versions from 9.20.0 to 9.20.20, as well as 9.21.0 to 9.21.19, are affected by CVE-2026-3591.
What kind of attacks can exploit CVE-2026-3591?
An attacker can exploit CVE-2026-3591 by sending specially-crafted DNS requests to bypass access control lists (ACLs).
Is the CVE-2026-3591 vulnerability present in all versions of BIND 9?
No, CVE-2026-3591 is not present in versions of BIND 9 released after the patched versions 9.20.21 and 9.21.20.