An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.
On 21 January 2026, Internet Systems Consortium disclosed one vulnerability affecting our BIND 9 software:
- CVE-2025-13878: Malformed BRID/HHIT records can cause named to terminate unexpectedly https://kb.isc.org/docs/cve-2025-13878
New versions of BIND 9 are available:
- https://downloads.isc.org/isc/bind9/9.18.44/ - https://downloads.isc.org/isc/bind9/9.20.18/ - https://downloads.isc.org/isc/bind9/9.21.17/
Operators and package maintainers who prefer to apply patches selectively can find individual vulnerability-specific patches in the "patches" subdirectory of each above directory.
For more information and other release formats, consult the ISC software download page: https://www.isc.org/download/
With the public announcement of these vulnerabilities, the embargo period is ended and any updated software packages that have been prepared may be released.
-- Best regards, Michał Kępień
On 25 March 2026, Internet Systems Consortium disclosed four vulnerabilities affecting our BIND 9 software:
- CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation https://kb.isc.org/docs/cve-2026-1519 - CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence https://kb.isc.org/docs/cve-2026-3104 - CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly https://kb.isc.org/docs/cve-2026-3119 - CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass https://kb.isc.org/docs/cve-2026-3591
New versions of BIND 9 are available:
- https://downloads.isc.org/isc/bind9/9.18.47/ - https://downloads.isc.org/isc/bind9/9.20.21/ - https://downloads.isc.org/isc/bind9/9.21.20/
For more information and other release formats, consult the ISC software download page: https://www.isc.org/download/
With the public announcement of these vulnerabilities, the embargo period is ended and any updated software packages that have been prepared may be released.
-- Nicki Křížek (they/them)
On 20 May 2026, Internet Systems Consortium disclosed six vulnerabilities affecting our BIND 9 software:
- CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation https://kb.isc.org/docs/cve-2026-3039 - CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records https://kb.isc.org/docs/cve-2026-3592 - CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation https://kb.isc.org/docs/cve-2026-3593 - CVE-2026-5946: Invalid handling of CLASS != IN https://kb.isc.org/docs/cve-2026-5946 - CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior https://kb.isc.org/docs/cve-2026-5947 - CVE-2026-5950: Unbounded resend loop in BIND 9 resolver https://kb.isc.org/docs/cve-2026-5950
New versions of BIND 9 are available:
- https://downloads.isc.org/isc/bind9/9.18.49/ - https://downloads.isc.org/isc/bind9/9.20.23/ - https://downloads.isc.org/isc/bind9/9.21.22/
For more information and other release formats, consult the ISC software download page: https://www.isc.org/download/
With the public announcement of these vulnerabilities, the embargo period is ended and any updated software packages that have been prepared may be released.
-- Best regards, Michał Kępień