PT-2026-27770 · Isc+4 · Bind+4
Bastien Roucariès
·
Publicado
2026-01-01
·
Atualizado
2026-05-21
·
CVE-2026-1519
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BIND versions 9.11.0 through 9.16.50
BIND versions 9.18.0 through 9.18.46
BIND versions 9.20.0 through 9.20.20
BIND versions 9.21.0 through 9.21.19
BIND versions 9.11.3-S1 through 9.16.50-S1
BIND versions 9.18.11-S1 through 9.18.46-S1
BIND versions 9.20.9-S1 through 9.20.20-S1
Description
A maliciously crafted DNS zone can cause excessive CPU consumption in a BIND resolver performing DNSSEC validation. Authoritative-only servers are generally not affected, but may be vulnerable if they make recursive queries.
Recommendations
Update BIND to a version beyond 9.16.50.
Update BIND to a version beyond 9.18.46.
Update BIND to a version beyond 9.20.20.
Update BIND to a version beyond 9.21.19.
Update BIND to a version beyond 9.16.50-S1.
Update BIND to a version beyond 9.18.46-S1.
Update BIND to a version beyond 9.20.20-S1.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bind
Bind Server
Linuxmint
Rocky Linux
Ubuntu