Search CVE reports


Toggle filters

1 – 10 of 120 results


CVE-2026-80274

Medium priority
Needs evaluation

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-77119

Medium priority
Needs evaluation

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50,...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-76163

Medium priority
Needs evaluation

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-75029

Medium priority
Needs evaluation

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set,...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-19668

Medium priority
Needs evaluation

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-19666

Medium priority
Needs evaluation

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-19033

Medium priority
Needs evaluation

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-81736

Medium priority
Needs evaluation

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-81563

Medium priority
Needs evaluation

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-78301

Medium priority
Needs evaluation

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages