Vulnerabilities · 173 days ago

BIND Updates Patch Two High-Severity DNSSEC DoS Flaws

The Internet Systems Consortium released BIND 9 updates that fix four vulnerabilities in resolver code. Two high-severity bugs can cause unbounded memory growth or high CPU during DNSSEC processing, which may lead to denial-of-service on affected resolvers.

CVE-2026-1519

NVD KEV

CVSS 7.5 HIGH: if a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. EPSS 2% (73rd percentile). Microsoft patch: CBL-Mariner Releases.

CVE-2026-3104

NVD KEV

CVSS 7.5 HIGH: a specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This… EPSS 0.7% (48th percentile). Microsoft patch: CBL-Mariner Releases.

CVE-2026-3119

NVD KEV

CVSS 6.5 MEDIUM: under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. EPSS 0.6% (43rd percentile), up from 0.02%. Microsoft patch: CBL-Mariner Releases.

CVE-2026-3591

NVD KEV

CVSS 5.4 MEDIUM: a use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). EPSS 0.4% (28th percentile). Microsoft patch: CBL-Mariner Releases.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-03-27

Editions

Related stories