https://seclists.org/oss-sec/2026/q2/625: ISC has disclosed six vulnerabilities in BIND 9 (CVE-2026-3039, CVE-2026-3592, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950)
Published May 20, 2026
·Updated
Affected Software
1 affected component
Internet Systems Consortium BIND 9<9.18.49, <9.20.23, <9.21.22
Frequently Asked Questions
1
What is the severity of CVE-2026-3039?
CVE-2026-3039 is classified as a medium-severity vulnerability due to its potential for memory exhaustion.
2
How do I fix CVE-2026-3039?
To fix CVE-2026-3039, upgrade to the latest version of BIND 9 that addresses this vulnerability.
3
What can happen if CVE-2026-3592 is exploited?
Exploitation of CVE-2026-3592 can result in a denial of service due to amplification attacks.
4
Are there workarounds for CVE-2026-3593?
There are no recommended workarounds for CVE-2026-3593; updating to a patched version is necessary.
5
What impact does CVE-2026-5950 have on BIND 9 installations?
CVE-2026-5950 may lead to unexpected behavior or service interruptions in BIND 9 installations.