CVE-2026-42387: Insufficient input validation in ZoneToCache
Published Jun 25, 2026
·Updated
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.
Affected Software
1 affected component
ISC BIND Recursor
Event History
Jun 25, 2026
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42387?
The severity of CVE-2026-42387 is medium with a score of 5.9.
2
What vulnerability does CVE-2026-42387 pertain to?
CVE-2026-42387 pertains to insufficient input validation in the ZoneToCache function of ISC BIND Recursor.
3
How can I fix CVE-2026-42387?
To fix CVE-2026-42387, update to the latest version of ISC BIND Recursor that addresses the insufficient input validation issue.
4
What impact does CVE-2026-42387 have on system stability?
CVE-2026-42387 can lead to a crash of the Recursor if a malicious authoritative server sends a crafted zone.
5
Who is affected by CVE-2026-42387?
CVE-2026-42387 affects users of ISC BIND Recursor due to its insufficient input validation vulnerability.