PT-2026-42163 · Isc+5 · Bind 9+5

·

CVE-2026-5946

·

Published

2026-05-13

·

Updated

2026-07-06

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.0 through 9.16.50 BIND 9 versions 9.18.0 through 9.18.48 BIND 9 versions 9.20.0 through 9.20.22 BIND 9 versions 9.21.0 through 9.21.21 BIND 9 versions 9.11.3-S1 through 9.16.50-S1 BIND 9 versions 9.18.11-S1 through 9.18.48-S1 BIND 9 versions 9.20.9-S1 through 9.20.22-S1
Description Multiple flaws exist in named regarding the handling of DNS messages where the CLASS is not Internet (IN), such as CHAOS or HESIOD, or messages specifying meta-classes like ANY or NONE in the question section. Specially crafted requests targeting code paths related to recursion, dynamic updates (UPDATE), zone change notifications (NOTIFY), or the processing of IN-specific record types in non-IN data can trigger assertion failures in named.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Assertion Failure

RCE

Type Confusion

Improper Check for Exceptional Conditions

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:23360
ALSA-2026:24338
ALSA-2026:24339
ALSA-2026:24367
ALSA-2026:24368
BDU:2026-08887
CLSA-2026-1780406874
CVE-2026-5946
ECHO-A977-35CE-16DF
OESA-2026-2655
OESA-2026-2656
OPENSUSE-SU-2026:10874-1
OPENSUSE-SU-2026:21123-1
RHSA-2026:20334
RHSA-2026:23360
RHSA-2026:24338
RHSA-2026:24339
RHSA-2026:24367
RHSA-2026:24368
SUSE-SU-2026:22198-1
SUSE-SU-2026:2289-1
SUSE-SU-2026:2616-1
SUSE-SU-2026:2617-1
SUSE-SU-2026:2673-1
SUSE-SU-2026:2676-1
SUSE-SU-2026:2779-1
USN-8293-1

Affected Products

Bind 9
Bind Server
Ibm Aix
Linuxmint
Rocky Linux
Ubuntu