CVE-2026-77692
Description
A flaw was found in BIND, a widely used Domain Name System (DNS) software. A remote attacker can exploit this vulnerability by sending a specially crafted DNS-over-HTTPS (DoH) request containing an invalid SIG(0) record. This action, combined with prematurely closing the connection, can cause the named daemon to unexpectedly terminate, leading to a Denial of Service (DoS) for affected systems.
Statement
Important: A remote denial of service vulnerability exists in the BIND named service. An attacker can send a specially crafted DNS-over-HTTPS request with an invalid SIG(0) record and prematurely close the connection, causing the named process to abort. This can lead to service unavailability.
Mitigation
To mitigate this issue, restrict access to the BIND service to trusted clients only, or disable DNS-over-HTTPS if it is not required.
To restrict network access to the BIND service, configure firewall rules to only allow connections from trusted IP ranges to port 53 (UDP and TCP). For example, using `firewalld`:
`firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="53" protocol="udp" accept'`
`firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="53" protocol="tcp" accept'`
`firewall-cmd --reload`
If DNS-over-HTTPS is enabled and not essential, consider disabling it in the BIND configuration. Refer to the BIND administrator's reference manual for instructions on disabling DNS-over-HTTPS. Changes to BIND configuration require a restart of the `named` service for them to take effect.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.5 | N/A | 7.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.