Resource exhaustion in ISC BIND - CVE-2026-5950
Published: May 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control of resource consumption in the resolver state machine bad-server handling in BIND 9 when processing queries that trigger specific retry conditions. A remote attacker can send specially crafted queries to cause a denial of service.
Resolvers are affected, while authoritative services are believed to be unaffected.
Affected software
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
Server Applications Module
openSUSE Leap
Ubuntu
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
bind9 (Ubuntu package)
bind-libs
bind-license
bind-doc
bind-dnssec-doc
bind-utils
bind-dnssec-utils
bind-devel
bind-chroot
bind
bind9 (Debian package)
bind-debugsource
bind-utils-debuginfo
bind-debuginfo
bind9-next
bind-dyndb-ldap
How to mitigate CVE-2026-5950
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.4, 1:9.18.39-0ubuntu0.24.04.5, 1:9.20.11-1ubuntu2.4, 1:9.20.18-1ubuntu2.1
bind-libs - update to 9.18.49-1
bind-license - update to 9.18.49-1
bind-doc - update to 9.18.49-1
bind-dnssec-doc - update to 9.18.49-1
bind-utils - update to 9.18.49-1
bind-dnssec-utils - update to 9.18.49-1
bind-devel - update to 9.18.49-1
bind-chroot - update to 9.18.49-1
bind - update to 9.18.49-1
bind - addressed in versions 9.18.49-1.fc42, 9.18.49-1.fc43, 9.18.49-1.fc44
bind9 (Debian package) - addressed in versions 1:9.18.49-1~deb12u1, 1:9.20.23-1~deb13u1
bind-doc - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-debugsource - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-utils-debuginfo - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-debuginfo - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-utils - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind - addressed in versions 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind9-next - addressed in versions 9.21.22-2.fc43, 9.21.22-2.fc44
bind-dyndb-ldap - addressed in versions 11.11-12.fc42, 11.11-13.fc43, 11.11-15.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Debian update for bind9
- Fedora 44 update for bind, bind-dyndb-ldap
- Fedora 43 update for bind, bind-dyndb-ldap
- Ubuntu update for bind9
- Fedora 42 update for bind, bind-dyndb-ldap
- Fedora 44 update for bind9-next
- Fedora 43 update for bind9-next
- Anolis OS update for bind
- SUSE update for bind
- SUSE update for bind
- Multiple vulnerabilities in Meinberg LANTIME Operating System Firmware