Resource exhaustion in ISC BIND - CVE-2026-3592
Published: May 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of self-pointed glue records in BIND resolver processing when resolving names in a specially crafted zone. A remote attacker can induce the resolver to query a specially crafted zone to cause a denial of service.
The issue predominantly affects recursive resolvers. Authoritative-only servers containing only trustworthy zones and names are believed to be unaffected.
Affected software
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Multi-Linux Manager Client Tools for SLE Micro
Server Applications Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
dhcp-help
dhcp-devel
dhcp-debugsource
dhcp-debuginfo
dhcp
bind
bind-export-devel
bind-chroot
bind-debuginfo
bind-debugsource
bind-devel
bind-export-libs
bind-libs
bind-libs-lite
bind-pkcs11
bind-pkcs11-devel
bind-utils
python3-bind
libirs161-debuginfo
libisccfg163
liblwres161
libdns1110
liblwres161-debuginfo
libisccfg163-debuginfo
bind-chrootenv
libisccc161
bind-utils-debuginfo
libbind9-161-debuginfo
libdns1110-debuginfo
libbind9-161
libirs161
libisc1107-debuginfo
libisc1107
libisccc161-debuginfo
bind-doc
python-bind
libisc1107-32bit
libisc1107-debuginfo-32bit
libisc1606-64bit
libisccfg1600
libisccc1600
libisc1606-debuginfo
libisccc1600-64bit
libbind9-1600-64bit
libdns1605-64bit
libbind9-1600-debuginfo
libirs1601-64bit
libisccfg1600-64bit
libirs1601
libisc1606
libirs1601-debuginfo
libdns1605-debuginfo
libns1604
libns1604-debuginfo
libbind9-1600
libisccfg1600-debuginfo
libdns1605
libisccc1600-debuginfo
libirs-devel
bind-dnssec-utils
bind-pkcs11-libs
bind-pkcs11-utils
bind-dnssec-doc
bind-license
bind9 (Ubuntu package)
bind9 (Debian package)
bind9-next
bind-dyndb-ldap
How to mitigate CVE-2026-3592
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
dhcp-help - update to 4.4.2-17
dhcp-devel - update to 4.4.2-17
dhcp-debugsource - update to 4.4.2-17
dhcp-debuginfo - update to 4.4.2-17
dhcp - update to 4.4.2-17
bind - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-export-devel - update to 9.11.21-24
bind-chroot - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-debuginfo - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-debugsource - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-devel - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-export-libs - update to 9.11.21-24
bind-libs - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-libs-lite - update to 9.11.21-24
bind-pkcs11 - addressed in versions 9.11.21-24, 9.16.23-30
bind-pkcs11-devel - addressed in versions 9.11.21-24, 9.16.23-30
bind-utils - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
python3-bind - addressed in versions 9.11.21-24, 9.16.23-30
libirs161-debuginfo - update to 9.11.22-3.71.1
libisccfg163 - update to 9.11.22-3.71.1
bind-utils - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
liblwres161 - update to 9.11.22-3.71.1
libdns1110 - update to 9.11.22-3.71.1
liblwres161-debuginfo - update to 9.11.22-3.71.1
libisccfg163-debuginfo - update to 9.11.22-3.71.1
bind-chrootenv - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1
libisccc161 - update to 9.11.22-3.71.1
bind-utils-debuginfo - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-debugsource - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-devel - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1
libbind9-161-debuginfo - update to 9.11.22-3.71.1
libdns1110-debuginfo - update to 9.11.22-3.71.1
libbind9-161 - update to 9.11.22-3.71.1
bind - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
libirs161 - update to 9.11.22-3.71.1
bind-debuginfo - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
libisc1107-debuginfo - update to 9.11.22-3.71.1
libisc1107 - update to 9.11.22-3.71.1
libisccc161-debuginfo - update to 9.11.22-3.71.1
bind-doc - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
python-bind - update to 9.11.22-3.71.1
libisc1107-32bit - update to 9.11.22-3.71.1
libisc1107-debuginfo-32bit - update to 9.11.22-3.71.1
libisc1606-64bit - update to 9.16.6-150000.12.91.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccc1600 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccc1600-64bit - update to 9.16.6-150000.12.91.1
libbind9-1600-64bit - update to 9.16.6-150000.12.91.1
libdns1605-64bit - update to 9.16.6-150000.12.91.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libirs1601-64bit - update to 9.16.6-150000.12.91.1
libisccfg1600-64bit - update to 9.16.6-150000.12.91.1
python3-bind - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1
libirs1601 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisc1606 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libns1604 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libdns1605 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libirs-devel - update to 9.16.6-150300.22.59.1
bind-dnssec-utils - addressed in versions 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-pkcs11-libs - update to 9.16.23-30
bind-pkcs11-utils - update to 9.16.23-30
bind-dnssec-doc - addressed in versions 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-license - addressed in versions 9.16.23-30, 9.18.21-8, 9.18.21-9
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.4, 1:9.18.39-0ubuntu0.24.04.5, 1:9.20.11-1ubuntu2.4, 1:9.20.18-1ubuntu2.1
bind - update to 9.18.49-1
bind-chroot - update to 9.18.49-1
bind-devel - update to 9.18.49-1
bind-dnssec-utils - update to 9.18.49-1
bind-libs - update to 9.18.49-1
bind-utils - update to 9.18.49-1
bind-dnssec-doc - update to 9.18.49-1
bind-doc - update to 9.18.49-1
bind-license - update to 9.18.49-1
bind - addressed in versions 9.18.49-1.fc42, 9.18.49-1.fc43, 9.18.49-1.fc44
bind9 (Debian package) - addressed in versions 1:9.18.49-1~deb12u1, 1:9.20.23-1~deb13u1
bind9-next - addressed in versions 9.21.22-2.fc43, 9.21.22-2.fc44
bind-dyndb-ldap - addressed in versions 11.11-12.fc42, 11.11-13.fc43, 11.11-15.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Debian update for bind9
- Fedora 44 update for bind, bind-dyndb-ldap
- Fedora 43 update for bind, bind-dyndb-ldap
- Ubuntu update for bind9
- Fedora 42 update for bind, bind-dyndb-ldap
- Fedora 44 update for bind9-next
- Fedora 43 update for bind9-next
- openEuler 24.03 LTS SP1 update for bind
- openEuler 24.03 LTS SP3 update for bind
- SUSE update for bind
- Anolis OS update for bind
- openEuler 22.03 LTS SP4 update for bind
- openEuler 20.03 LTS SP4 update for bind
- openEuler update for dhcp
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- Multiple vulnerabilities in Meinberg LANTIME Operating System Firmware