Operation on a Resource after Expiration or Release in ISC BIND - CVE-2026-3591

 

Operation on a Resource after Expiration or Release in ISC BIND - CVE-2026-3591

Published: March 25, 2026


Vulnerability identifier: #VU124613
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3591
CWE-ID: CWE-672
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass access controls.

The vulnerability exists due to a use-after-return error in the SIG(0) handling code in named when processing specially crafted DNS queries. A remote user can send a specially crafted DNS request to cause an ACL to improperly (mis)match an IP address, potentially leading to unauthorized access in default-allow ACL configurations.

Authoritative servers and resolvers are affected. In a default-allow ACL (which denies only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail securely.


Affected software

ISC BIND
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
Ubuntu
Fedora
bind9 (Ubuntu package)
bind9 (Debian package)
bind-debuginfo
bind-utils
bind-utils-debuginfo
bind-debugsource
bind
bind-doc
bind9-next

How to mitigate CVE-2026-3591

Install security update from vendor's website.

ISC BIND - addressed in versions 9.20.21, 9.20.21-S1, 9.21.20
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.3, 1:9.18.39-0ubuntu0.24.04.3, 1:9.20.11-1ubuntu2.2
bind9 (Debian package) - addressed in versions 1:9.18.47-1~deb12u1, 1:9.20.21-1~deb13u1
bind-debuginfo - update to 9.20.21-150700.3.18.1
bind-utils - update to 9.20.21-150700.3.18.1
bind-utils-debuginfo - update to 9.20.21-150700.3.18.1
bind-debugsource - update to 9.20.21-150700.3.18.1
bind - update to 9.20.21-150700.3.18.1
bind-doc - update to 9.20.21-150700.3.18.1
bind9-next - addressed in versions 9.21.20-1.fc42, 9.21.20-1.fc43, 9.21.20-1.fc44

External References

Related Security Bulletins