REDHAT-BUG-2504447: High severity ISC BIND vulnerability
Published Jul 21, 2026
·Updated
If a provably insecure domain is covered by both NSEC and NSEC3 at the parent, with an RRSIG for only one type, BIND exits with an assertion during validation.
Affected Software
1 affected component
ISC BIND
Event History
Jul 21, 2026
Data Sourced
via Red Hat·08:57 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2504447?
The severity of REDHAT-BUG-2504447 is high with a rating of 7.
2
How do I fix REDHAT-BUG-2504447?
To fix REDHAT-BUG-2504447, ensure that the DNSSEC records for the domain are correctly configured and consistent across NSEC and NSEC3.
3
What impact does REDHAT-BUG-2504447 have on ISC BIND?
REDHAT-BUG-2504447 can cause ISC BIND to exit with an assertion error during the validation of insecure domains.
4
What versions of ISC BIND are affected by REDHAT-BUG-2504447?
All versions of ISC BIND that implement both NSEC and NSEC3 validation and are configured with conflicting RRSIG types are affected by REDHAT-BUG-2504447.
5
Is there a workaround for REDHAT-BUG-2504447?
One potential workaround for REDHAT-BUG-2504447 is to avoid using inconsistent DNSSEC configurations in the affected domain.