Input validation error in ISC BIND - CVE-2026-11721

 

Input validation error in ISC BIND - CVE-2026-11721

Published: July 23, 2026


Vulnerability identifier: #VU139209
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-11721
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ISC
Affected software:
ISC BIND

Detailed vulnerability description

The vulnerability allows a remote attacker to poison the DNS cache.

The vulnerability exists due to improper input validation in named when processing DNS responses containing an RRSIG with fewer labels than the containing zone and wildcard records. A remote attacker can operate an authoritative zone that returns a specially crafted response to poison the DNS cache.

The issue has effect only when the resolver under attack has synth-from-dnssec yes; enabled, which is the default.


How to mitigate CVE-2026-11721

Install security update from vendor's website.

Sources