Resource exhaustion in ISC BIND - CVE-2026-5950

 

Resource exhaustion in ISC BIND - CVE-2026-5950

Published: May 22, 2026


Vulnerability identifier: #VU132114
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-5950
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper control of resource consumption in the resolver state machine bad-server handling in BIND 9 when processing queries that trigger specific retry conditions. A remote attacker can send specially crafted queries to cause a denial of service.

Resolvers are affected, while authoritative services are believed to be unaffected.


Affected software

ISC BIND
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
Server Applications Module
openSUSE Leap
Ubuntu
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
bind9 (Ubuntu package)
bind-libs
bind-license
bind-doc
bind-dnssec-doc
bind-utils
bind-dnssec-utils
bind-devel
bind-chroot
bind
bind9 (Debian package)
bind-debugsource
bind-utils-debuginfo
bind-debuginfo
bind9-next
bind-dyndb-ldap

How to mitigate CVE-2026-5950

Install security update from vendor's website.

ISC BIND - addressed in versions 9.18.49, 9.18.49-S1, 9.20.23, 9.20.23-S1, 9.21.22
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.4, 1:9.18.39-0ubuntu0.24.04.5, 1:9.20.11-1ubuntu2.4, 1:9.20.18-1ubuntu2.1
bind-libs - update to 9.18.49-1
bind-license - update to 9.18.49-1
bind-doc - update to 9.18.49-1
bind-dnssec-doc - update to 9.18.49-1
bind-utils - update to 9.18.49-1
bind-dnssec-utils - update to 9.18.49-1
bind-devel - update to 9.18.49-1
bind-chroot - update to 9.18.49-1
bind - update to 9.18.49-1
bind - addressed in versions 9.18.49-1.fc42, 9.18.49-1.fc43, 9.18.49-1.fc44
bind9 (Debian package) - addressed in versions 1:9.18.49-1~deb12u1, 1:9.20.23-1~deb13u1
bind-doc - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-debugsource - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-utils-debuginfo - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-debuginfo - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-utils - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind9-next - addressed in versions 9.21.22-2.fc43, 9.21.22-2.fc44
bind-dyndb-ldap - addressed in versions 11.11-12.fc42, 11.11-13.fc43, 11.11-15.fc44

External References

Related Security Bulletins