CVE-2026-5950: Unbounded resend loop in BIND 9 resolver
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
Other sources
Unbounded resend loop in BIND 9 resolver
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/bind9to a version that resolves this vulnerability.Fixed in 1:9.18.49-1~deb12u1Fixed in 1:9.20.23-1~deb13u1Fixed in 1:9.20.23-1 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.18.49 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.23 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.21.22 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.18.49-S1 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.23-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5950?
CVE-2026-5950 is classified as a critical severity vulnerability that can lead to severe resource exhaustion.
How do I fix CVE-2026-5950?
To mitigate CVE-2026-5950, upgrade to the latest versions of BIND 9 that address this issue.
What software is affected by CVE-2026-5950?
CVE-2026-5950 affects specific versions of Internet Systems Consortium BIND 9, particularly between 9.18.36 and 9.18.48, among others.
What type of attack does CVE-2026-5950 enable?
CVE-2026-5950 allows remote unauthenticated attackers to exploit the BIND 9 resolver to create an unbounded resend loop, resulting in resource exhaustion.
How can CVE-2026-5950 impact my system?
CVE-2026-5950 can lead to denial of service on affected systems by overwhelming them with continuous query retries.