Memory leak in ISC BIND - CVE-2026-3039
Published: May 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the GSS-API TKEY negotiation handling in BIND 9 when processing maliciously constructed packets. A remote attacker can send specially crafted packets to cause a denial of service.
Only servers configured to use TKEY-based authentication via GSS-API tokens are vulnerable.
Affected software
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Multi-Linux Manager Client Tools for SLE Micro
Anolis OS
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - AUS
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Fedora
LANTIME Operating System Firmware (LTOS)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind-export-devel
python3-bind
bind-utils
bind-pkcs11-devel
bind-pkcs11
bind-libs-lite
bind-libs
bind
bind-chroot
bind-debuginfo
bind-debugsource
bind-devel
bind-export-libs
libirs161-debuginfo
libisccc161
bind-chrootenv
libisccfg163-debuginfo
liblwres161-debuginfo
libdns1110
liblwres161
libisc1107-32bit
libisccfg163
libbind9-161-debuginfo
libdns1110-debuginfo
libbind9-161
libirs161
libisc1107-debuginfo
libisc1107
libisccc161-debuginfo
bind-doc
python-bind
libisc1107-debuginfo-32bit
bind-utils-debuginfo
bind-lite-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-license
libns1604-debuginfo
libisccc1600-debuginfo
libbind9-1600-debuginfo
libisc1606-debuginfo
libisccc1600
libisccfg1600
libirs1601
libdns1605
libisccfg1600-debuginfo
libbind9-1600
libisc1606-64bit
libns1604
libdns1605-64bit
libbind9-1600-64bit
libisccc1600-64bit
libirs1601-64bit
libisccfg1600-64bit
libisc1606
libirs1601-debuginfo
libdns1605-debuginfo
libirs-devel
bind9.16-libs
bind9.16
bind9.16-chroot
bind9.16-devel
python3-bind9.16
bind9.16-license
bind9.16-doc
bind9.16-utils
bind9.16-dnssec-utils
bind9.16 (Red Hat package)
bind (Red Hat package) main
bind-dnssec-utils
bind-dnssec-doc
bind9 (Ubuntu package)
bind9 (Debian package)
bind9-next
bind-dyndb-ldap
How to mitigate CVE-2026-3039
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
bind-export-devel - update to 9.11.21-24
python3-bind - addressed in versions 9.11.21-24, 9.16.23-30
bind-utils - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-pkcs11-devel - addressed in versions 9.11.21-24, 9.16.23-30
bind-pkcs11 - addressed in versions 9.11.21-24, 9.16.23-30
bind-libs-lite - update to 9.11.21-24
bind-libs - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-chroot - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-debuginfo - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-debugsource - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-devel - addressed in versions 9.11.21-24, 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-export-libs - update to 9.11.21-24
bind-devel - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1
bind-debugsource - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
libirs161-debuginfo - update to 9.11.22-3.71.1
libisccc161 - update to 9.11.22-3.71.1
bind-chrootenv - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1
libisccfg163-debuginfo - update to 9.11.22-3.71.1
liblwres161-debuginfo - update to 9.11.22-3.71.1
libdns1110 - update to 9.11.22-3.71.1
liblwres161 - update to 9.11.22-3.71.1
bind-utils - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
libisc1107-32bit - update to 9.11.22-3.71.1
libisccfg163 - update to 9.11.22-3.71.1
libbind9-161-debuginfo - update to 9.11.22-3.71.1
libdns1110-debuginfo - update to 9.11.22-3.71.1
libbind9-161 - update to 9.11.22-3.71.1
bind - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
libirs161 - update to 9.11.22-3.71.1
libisc1107-debuginfo - update to 9.11.22-3.71.1
libisc1107 - update to 9.11.22-3.71.1
libisccc161-debuginfo - update to 9.11.22-3.71.1
bind-doc - addressed in versions 9.11.22-3.71.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
python-bind - update to 9.11.22-3.71.1
libisc1107-debuginfo-32bit - update to 9.11.22-3.71.1
bind-debuginfo - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind-utils-debuginfo - addressed in versions 9.11.22-3.71.1, 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1, 9.18.49-150600.3.26.1, 9.20.23-150700.3.25.1
bind - addressed in versions 9.11.36-16.0.1, 9.18.49-1
bind-lite-devel - update to 9.11.36-16.0.1
bind-chroot - addressed in versions 9.11.36-16.0.1, 9.18.49-1
bind-devel - addressed in versions 9.11.36-16.0.1, 9.18.49-1
bind-export-devel - update to 9.11.36-16.0.1
bind-export-libs - update to 9.11.36-16.0.1
bind-libs - addressed in versions 9.11.36-16.0.1, 9.18.49-1
bind-libs-lite - update to 9.11.36-16.0.1
bind-pkcs11 - update to 9.11.36-16.0.1
bind-pkcs11-devel - update to 9.11.36-16.0.1
bind-pkcs11-libs - update to 9.11.36-16.0.1
bind-pkcs11-utils - update to 9.11.36-16.0.1
bind-sdb - update to 9.11.36-16.0.1
bind-sdb-chroot - update to 9.11.36-16.0.1
bind-utils - addressed in versions 9.11.36-16.0.1, 9.18.49-1
bind-license - addressed in versions 9.11.36-16.0.1, 9.18.49-1
python3-bind - update to 9.11.36-16.0.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccc1600 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libirs1601 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libdns1605 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libisc1606-64bit - update to 9.16.6-150000.12.91.1
libns1604 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libdns1605-64bit - update to 9.16.6-150000.12.91.1
libbind9-1600-64bit - update to 9.16.6-150000.12.91.1
libisccc1600-64bit - update to 9.16.6-150000.12.91.1
libirs1601-64bit - update to 9.16.6-150000.12.91.1
libisccfg1600-64bit - update to 9.16.6-150000.12.91.1
python3-bind - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1, 9.16.50-150400.5.62.1, 9.16.50-150500.8.38.1
libisc1606 - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.91.1, 9.16.6-150300.22.59.1
libirs-devel - update to 9.16.6-150300.22.59.1
bind9.16-libs - update to 9.16.23-0.22
bind9.16 - update to 9.16.23-0.22
bind9.16-chroot - update to 9.16.23-0.22
bind9.16-devel - update to 9.16.23-0.22
python3-bind9.16 - update to 9.16.23-0.22
bind9.16-license - update to 9.16.23-0.22
bind9.16-doc - update to 9.16.23-0.22
bind9.16-utils - update to 9.16.23-0.22
bind9.16-dnssec-utils - update to 9.16.23-0.22
bind9.16 (Red Hat package) - update to 9.16.23-0.22.el8_10.6
bind (Red Hat package) main - addressed in versions 9.16.23-18.el9_4.12, 9.16.23-40.el9_8.2
bind-license - addressed in versions 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-dnssec-utils - addressed in versions 9.16.23-30, 9.18.21-8, 9.18.21-9
bind-pkcs11-libs - update to 9.16.23-30
bind-pkcs11-utils - update to 9.16.23-30
bind-dnssec-doc - addressed in versions 9.16.23-30, 9.18.21-8, 9.18.21-9
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.4, 1:9.18.39-0ubuntu0.24.04.5, 1:9.20.11-1ubuntu2.4, 1:9.20.18-1ubuntu2.1
bind-doc - update to 9.18.49-1
bind-dnssec-utils - update to 9.18.49-1
bind-dnssec-doc - update to 9.18.49-1
bind - addressed in versions 9.18.49-1.fc42, 9.18.49-1.fc43, 9.18.49-1.fc44
bind9 (Debian package) - addressed in versions 1:9.18.49-1~deb12u1, 1:9.20.23-1~deb13u1
bind9-next - addressed in versions 9.21.22-2.fc43, 9.21.22-2.fc44
bind-dyndb-ldap - addressed in versions 11.11-12.fc42, 11.11-13.fc43, 11.11-15.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Debian update for bind9
- Fedora 44 update for bind, bind-dyndb-ldap
- Fedora 43 update for bind, bind-dyndb-ldap
- Ubuntu update for bind9
- Fedora 42 update for bind, bind-dyndb-ldap
- Red Hat Enterprise Linux 8 update for bind9.16
- Fedora 44 update for bind9-next
- Fedora 43 update for bind9-next
- openEuler 24.03 LTS SP1 update for bind
- openEuler 24.03 LTS SP3 update for bind
- SUSE update for bind
- Red Hat Enterprise Linux 9 update for bind
- Anolis OS update for bind
- Anolis OS update for bind
- Anolis OS update for bind9.16
- openEuler 22.03 LTS SP4 update for bind
- openEuler 20.03 LTS SP4 update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- Multiple vulnerabilities in Meinberg LANTIME Operating System Firmware
- Red Hat Enterprise Linux 9 update for bind