Input validation error in ISC BIND - CVE-2019-6469
Published: July 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the EDNS Client Subnet (ECS) feature for recursive resolvers when processing a response with malformed RRSIGs. A remote attacker can cause a server to perform a query whose answer is accompanied by malformed RRSIGs to cause a denial of service.
Only servers using the recursive ECS feature are vulnerable.