CVE-2026-19662
Description
A flaw was found in BIND 9. A remote attacker can cause a named resolver to stop functioning (Denial of Service) by inducing the victim resolver to send multiple queries for a DNSSEC-signed zone. If the attacker's authoritative server responds with a specific sequence of crafted answers that arrive with particular timing, a use-after-free vulnerability is triggered, leading to the resolver's abortion.
Statement
This Moderate impact denial of service vulnerability in BIND 9's named resolver can lead to service unavailability. Exploitation requires an attacker to operate an authoritative DNS server and specifically induce a vulnerable resolver to query it for a DNSSEC-signed zone. The attack relies on a precise sequence and timing of crafted DNSSEC responses, limiting its broader applicability.
Mitigation
To mitigate this issue, consider disabling DNSSEC validation on `named` resolvers if it is not a strict requirement for your environment. This can be achieved by setting `dnssec-validation no;` in the `named.conf` file. Disabling DNSSEC validation will prevent the resolver from processing DNSSEC-signed zones, thereby avoiding this specific vulnerability, but it will also remove the security benefits provided by DNSSEC. After modifying the configuration, the `named` service must be reloaded or restarted for the changes to take effect.
`sudo systemctl reload named`
`sudo systemctl restart named`
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.9 | N/A | 5.9 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Memory
If the expired pointer is used in a read operation, an attacker might be able to control data read in by the application.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the expired pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
If the expired pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.