Resource exhaustion in ISC BIND - CVE-2026-11622
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the DNSSEC validating resolver when processing queries during a random subdomain attack against a DNSSEC-signed zone. A remote attacker can send queries faster than the resolver can perform validation to cause a denial of service.
Only DNSSEC validating resolvers targeted with a random subdomain attack against a DNSSEC-signed zone are affected.