PT-2026-42155 · Isc+3 · Bind+3

Published

2026-05-17

·

Updated

2026-05-28

·

CVE-2026-3592

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions BIND versions 9.11.0 through 9.16.50 BIND versions 9.18.0 through 9.18.48 BIND versions 9.20.0 through 9.20.22 BIND versions 9.21.0 through 9.21.21 BIND versions 9.11.3-S1 through 9.16.50-S1 BIND versions 9.18.11-S1 through 9.18.48-S1 BIND versions 9.20.9-S1 through 9.20.22-S1
Description BIND resolvers are susceptible to an amplified resource consumption and exhaustion attack via self-pointed glue records. This occurs when a victim resolver processes a query to a specially crafted zone, leading to the consumption of disproportionate system resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-3592
ECHO-5A68-58ED-E2E3
OPENSUSE-SU-2026:10874-1
RHSA-2026:20334
USN-8293-1

Affected Products

Bind
Bind Server
Linuxmint
Ubuntu