Vulnerabilidades de BIND

Vulnerabilidades del servidor DNS BIND de ISC. Ahora mismo seguimos 23 avisos, 23 con versión corregida publicada.

CVE-2026-19033 Media 6.5 2026-09-16

BIND

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an…

Corregida en Debian 13 y Debian 14.

CVE-2026-19662 Media 5.9 2026-09-16

BIND

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server…

Corregida en Debian 13 y Debian 14.

CVE-2026-19666 Alta 7.5 2026-09-16

BIND

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue…

Corregida en Debian 13 y Debian 14.

CVE-2026-19667 Alta 7.5 2026-09-16

BIND

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is…

Corregida en Debian 13 y Debian 14.

CVE-2026-19668 Media 5.3 2026-09-16

BIND

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and…

Corregida en Debian 13 y Debian 14.

CVE-2026-19941 Media 5.9 2026-09-16

BIND

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the…

Corregida en Debian 13 y Debian 14.

CVE-2026-75029 Media 5.3 2026-09-16

BIND

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended…

Corregida en Debian 13 y Debian 14.

CVE-2026-76163 Alta 7.5 2026-09-16

BIND

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected…

Corregida en Debian 13 y Debian 14.

CVE-2026-77119 Media 5.9 2026-09-16

BIND

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9…

Corregida en Debian 13 y Debian 14.

CVE-2026-77692 Alta 7.5 2026-09-16

BIND

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue…

Corregida en Debian 13 y Debian 14.

CVE-2026-78301 Media 5.8 2026-09-16

BIND

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone…

Corregida en Debian 13 y Debian 14.

CVE-2026-80274 Alta 7.5 2026-09-16

BIND

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the…

Corregida en Debian 13 y Debian 14.

CVE-2026-81563 Alta 7.5 2026-09-16

BIND

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly…

Corregida en Debian 13 y Debian 14.

CVE-2026-81736 Alta 7.5 2026-09-16

BIND

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This…

Corregida en Debian 13 y Debian 14.

CVE-2026-13204 Sin clasificar 2026-08-31

BIND

bind9 vulnerability

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-10723 Sin clasificar 2026-08-19

BIND

bind9 vulnerabilities

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-10822 Media 6.5 2026-07-22

BIND

Si BIND encuentra una estructura de datos inválida particular en un registro DNS, aceptará los datos inválidos, y posteriormente puede abortar y cerrarse. BIND primero necesitará almacenar un…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-11331 Alta 7.5 2026-07-22

BIND

Un atacante que sepa (o adivine) que un resolutor usa RPZ con políticas CNAME comodín puede crear nombres de consulta lo suficientemente largos como para provocar una condición de error NAMETOOLONG…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-11605 Alta 7.5 2026-07-22

BIND

El problema es una vulnerabilidad de agotamiento de recursos asociada a la validación DNSSEC. BIND siempre valida todos los registros RRSIG de una respuesta, incluso si no son estrictamente…

Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.

CVE-2026-11622 Alta 7.5 2026-07-22

BIND

Un resolutor validador de DNSSEC que esté bajo un ataque de subdominios aleatorios contra una zona firmada con DNSSEC puede sufrir un uso descontrolado de memoria. El atacante necesita ser capaz de…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-11721 Alta 7.5 2026-07-22

BIND

Es posible que la zona de un atacante responda a una consulta con un RRSIG que tenga un número de etiquetas menor que la zona en la que está contenido el RRSIG. Esto hace que `named` produzca un…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-12617 Alta 7.5 2026-07-22

BIND

El problema es una terminación inesperada del programa basada en el orden y/o el contenido específico en respuestas a consultas de registros CNAME o DNAME, y A. Específicamente, si un cliente…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-13321 Alta 8.6 2026-07-22

BIND

El resolutor de BIND acepta registros NSEC firmados válidamente donde el campo "Next Domain Name" apunta fuera de la zona del firmante. Este problema afecta a BIND 9 versiones 9.11.0 a 9.18.50…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.