CVE-2026-77692

Description

A flaw was found in BIND, a widely used Domain Name System (DNS) software. A remote attacker can exploit this vulnerability by sending a specially crafted DNS-over-HTTPS (DoH) request containing an invalid SIG(0) record. This action, combined with prematurely closing the connection, can cause the named daemon to unexpectedly terminate, leading to a Denial of Service (DoS) for affected systems.

Statement

Important: A remote denial of service vulnerability exists in the BIND named service. An attacker can send a specially crafted DNS-over-HTTPS request with an invalid SIG(0) record and prematurely close the connection, causing the named process to abort. This can lead to service unavailability.

Mitigation

To mitigate this issue, restrict access to the BIND service to trusted clients only, or disable DNS-over-HTTPS if it is not required.
To restrict network access to the BIND service, configure firewall rules to only allow connections from trusted IP ranges to port 53 (UDP and TCP). For example, using `firewalld`:
`firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="53" protocol="udp" accept'`
`firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="53" protocol="tcp" accept'`
`firewall-cmd --reload`
If DNS-over-HTTPS is enabled and not essential, consider disabling it in the BIND configuration. Refer to the BIND administrator's reference manual for instructions on disabling DNS-over-HTTPS. Changes to BIND configuration require a restart of the `named` service for them to take effect.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.5N/A7.5
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.

Frequently Asked Questions

Want to get errata notifications? Sign up here.