Resource exhaustion in ISC BIND - CVE-2026-11605
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to resource exhaustion in DNSSEC validation when processing answers containing many valid but superfluous RRSIG records. A remote attacker can send a query that triggers validation of such records to cause a denial of service.
The issue results in disproportionate CPU consumption during validation.