Vulnerabilità · 190 giorni fa

ISC rilascia patch per BIND 9 contro DoS DNSSEC

Internet Systems Consortium ha rilasciato aggiornamenti per BIND 9 che correggono quattro vulnerabilità nel codice resolver.

CVE-2026-1519

NVD KEV

CVSS 7.5 HIGH: if a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. EPSS 2% (73º percentile). Patch Microsoft: CBL-Mariner Releases.

CVE-2026-3104

NVD KEV

CVSS 7.5 HIGH: a specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This… EPSS 1% (66º percentile). Patch Microsoft: CBL-Mariner Releases.

CVE-2026-3119

NVD KEV

CVSS 6.5 MEDIUM: under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. EPSS 0.6% (46º percentile). Patch Microsoft: CBL-Mariner Releases.

CVE-2026-3591

NVD KEV

CVSS 5.4 MEDIUM: a use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). EPSS 0.3% (23º percentile). Patch Microsoft: CBL-Mariner Releases.

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-03-27

Editions

Storie correlate