CVE-2026-1519
CVSS 7.5 HIGH: if a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. EPSS 2% (73º percentile). Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità ed exploit
Internet Systems Consortium ha rilasciato aggiornamenti per BIND 9 che correggono quattro vulnerabilità nel codice resolver.
1 fonte · 26 mar
CVSS 7.5 HIGH: if a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. EPSS 2% (73º percentile). Patch Microsoft: CBL-Mariner Releases.
CVSS 7.5 HIGH: a specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This… EPSS 1% (66º percentile). Patch Microsoft: CBL-Mariner Releases.
CVSS 6.5 MEDIUM: under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. EPSS 0.6% (46º percentile). Patch Microsoft: CBL-Mariner Releases.
CVSS 5.4 MEDIUM: a use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). EPSS 0.3% (23º percentile). Patch Microsoft: CBL-Mariner Releases.
SecurityWeek
BIND Updates Patch High-Severity Vulnerabilities
Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers.
originalePart of the PlainSec briefing for 2026-03-27
Every edition of this story: ISC rilascia patch per BIND 9 contro DoS DNSSEC