Use-after-free in ISC BIND - CVE-2026-5947
Published: May 22, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in SIG(0) validation when processing a DNS message signed with SIG(0) while the recursive-clients limit is reached during a query flood. A remote attacker can send specially crafted DNS traffic to cause a denial of service.
Both authoritative servers and resolvers are affected.