Operation on a Resource after Expiration or Release in ISC BIND - CVE-2026-3591
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote user to bypass access controls.
The vulnerability exists due to a use-after-return error in the SIG(0) handling code in named when processing specially crafted DNS queries. A remote user can send a specially crafted DNS request to cause an ACL to improperly (mis)match an IP address, potentially leading to unauthorized access in default-allow ACL configurations.
Authoritative servers and resolvers are affected. In a default-allow ACL (which denies only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail securely.
Affected software
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
Ubuntu
Fedora
bind9 (Ubuntu package)
bind9 (Debian package)
bind-debuginfo
bind-utils
bind-utils-debuginfo
bind-debugsource
bind
bind-doc
bind9-next
How to mitigate CVE-2026-3591
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.3, 1:9.18.39-0ubuntu0.24.04.3, 1:9.20.11-1ubuntu2.2
bind9 (Debian package) - addressed in versions 1:9.18.47-1~deb12u1, 1:9.20.21-1~deb13u1
bind-debuginfo - update to 9.20.21-150700.3.18.1
bind-utils - update to 9.20.21-150700.3.18.1
bind-utils-debuginfo - update to 9.20.21-150700.3.18.1
bind-debugsource - update to 9.20.21-150700.3.18.1
bind - update to 9.20.21-150700.3.18.1
bind-doc - update to 9.20.21-150700.3.18.1
bind9-next - addressed in versions 9.21.20-1.fc42, 9.21.20-1.fc43, 9.21.20-1.fc44