Known vulnerabilities in bind9.16 (Red Hat package)
Vendor:
Red Hat Inc.
Software:
bind9.16 (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:bind9_16_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
13
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139214 - Improper input validation CVE-2026-10723 |
CWE-20 | Medium | 9.16.23-0.22.el8_10.12 | 23.07.2026 |
SB2026072347 SB2026072441 SB2026073103 and 21 more |
||
| #VU139212 - Improper Check or Handling of Exceptional Conditions CVE-2026-11331 |
CWE-703 | Medium | 9.16.23-0.22.el8_10.12 | 23.07.2026 |
SB2026072347 SB2026072441 SB2026073103 and 19 more |
||
| #VU139210 - Resource exhaustion CVE-2026-11622 |
CWE-400 | Medium | 9.16.23-0.22.el8_10.12 | 23.07.2026 |
SB2026072347 SB2026072441 SB2026073103 and 24 more |
||
| #VU139209 - Improper input validation CVE-2026-11721 |
CWE-20 | Medium | 9.16.23-0.22.el8_10.12 | 23.07.2026 |
SB2026072347 SB2026072441 SB2026073103 and 24 more |
||
| #VU139207 - Reachable Assertion CVE-2026-13204 |
CWE-617 | Medium | 9.16.23-0.22.el8_10.12 | 23.07.2026 |
SB2026072347 SB2026072441 SB2026073103 and 25 more |
||
| #VU139206 - Improper input validation CVE-2026-13321 |
CWE-20 | Low | 9.16.23-0.22.el8_10.12 | 23.07.2026 |
SB2026072347 SB2026072441 SB2026073103 and 24 more |
||
| #VU132119 - Missing release of memory after effective lifetime CVE-2026-3039 |
CWE-401 | Medium | 9.16.23-0.22.el8_10.6 | 22.05.2026 |
SB2026052202 SB2026052211 SB2026052212 and 25 more |
||
| #VU132116 - Improper Handling of Exceptional Conditions CVE-2026-5946 |
CWE-755 | Medium | 9.16.23-0.22.el8_10.6 | 22.05.2026 |
SB2026052202 SB2026052211 SB2026052212 and 25 more |
||
| #VU124616 - Resource exhaustion CVE-2026-1519 |
CWE-400 | Medium | 9.16.23-0.7.el8_6.10, 9.16.23-0.14.el8_8.8, 9.16.23-0.22.el8_10.5 | 25.03.2026 |
SB20260325207 SB20260325210 SB20260325211 and 40 more |
||
| #VU117610 - Insufficient Verification of Data Authenticity CVE-2025-40778 |
CWE-345 | Medium | 9.16.23-0.7.el8_6.9, 9.16.23-0.14.el8_8.7, 9.16.23-0.22.el8_10.4 | 23.10.2025 |
SB2025102373 SB2025102393 SB20251023133 and 60 more |
||
| #VU117604 - Predictable Seed in Pseudo-Random Number Generator (PRNG) CVE-2025-40780 |
CWE-337 | Medium | 9.16.23-0.7.el8_6.9, 9.16.23-0.14.el8_8.7, 9.16.23-0.22.el8_10.4 | 23.10.2025 |
SB2025102373 SB2025102393 SB20251023133 and 41 more |
||
| #VU103436 - Resource exhaustion CVE-2024-11187 |
CWE-400 | Medium | 9.16.23-0.7.el8_6.8, 9.16.23-0.14.el8_8.6, 9.16.23-0.22.el8_10.2 | 29.01.2025 |
SB2025012962 SB2025012964 SB2025012965 and 83 more |
||
| #VU61422 - Reliance on Reverse DNS Resolution for a Security-Critical Action CVE-2021-25220 |
CWE-350 | Medium | 9.16.23-0.7.el8_6.9 | 17.03.2022 |
SB2022031701 SB2022031719 SB2022031725 and 57 more |