Vulnerabilities · 4 days ago
ISC has released BIND 9.20.29, 9.21.26, and BIND Supported Preview Edition 9.20.29-S1 to fix 14 denial-of-service flaws, including seven rated high. One of the crashes needs only a crafted DNS-over-HTTPS request and no credentials: ISC says a bad SIG(0) signature and a closed connection can make named abort.
The mechanism is a service crash, not code execution. In the DoH case, the server starts checking the signature and dies if the sender drops the connection before that check finishes; other flaws can drain memory or CPU, or terminate the resolver under crafted DNS traffic.
The catch is the packaging gap: ISC ended support for 9.18 and shipped no 9.18 fix, yet some operating-system packages still carry 9.18 builds. For DNS operators and distro maintainers, the exposure now sits with downstream packaging as much as with ISC itself.
CVEs in this update
6 CVEs
Across BIND, BIND 9.
0 critical · 5 high · 1 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-80274 · 7.5 HIGH
Highest EPSS: CVE-2026-80274 · 0.49%
3 sources covering this story
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
ISC fixes 14 BIND 9 flaws, including an unauthenticated DoH request that can crash named; ISC reports no active exploits.
Risolte vulnerabilità in ISC BIND 9
ISC ha rilasciato aggiornamenti di sicurezza per BIND 9 e BIND Supported Preview Edition, software per la gestione e la risoluzione delle richieste DNS, che sanano alcune vulnerabilità, di cui 7 con gravità "alta".
Part of the PlainSec briefing for 2026-09-18