Memory leak in ISC BIND - CVE-2026-3039
Published: May 22, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the GSS-API TKEY negotiation handling in BIND 9 when processing maliciously constructed packets. A remote attacker can send specially crafted packets to cause a denial of service.
Only servers configured to use TKEY-based authentication via GSS-API tokens are vulnerable.