Resource exhaustion in ISC BIND - CVE-2026-11605
Published: July 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to resource exhaustion in DNSSEC validation when processing answers containing many valid but superfluous RRSIG records. A remote attacker can send a query that triggers validation of such records to cause a denial of service.
The issue results in disproportionate CPU consumption during validation.
Affected software
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
Ubuntu
openEuler
bind9 (Ubuntu package)
bind-debugsource
bind-license
bind-dnssec-doc
bind-utils
bind-libs
bind-dnssec-utils
bind-devel
bind-debuginfo
bind-chroot
bind
bind9 (Debian package)
bind-doc
bind-utils-debuginfo
How to mitigate CVE-2026-11605
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.5, 1:9.18.39-0ubuntu0.24.04.6, 1:9.20.24-1ubuntu0.2
bind-debugsource - update to 9.20.21-4
bind-license - update to 9.20.21-4
bind-dnssec-doc - update to 9.20.21-4
bind-utils - update to 9.20.21-4
bind-libs - update to 9.20.21-4
bind-dnssec-utils - update to 9.20.21-4
bind-devel - update to 9.20.21-4
bind-debuginfo - update to 9.20.21-4
bind-chroot - update to 9.20.21-4
bind - update to 9.20.21-4
bind9 (Debian package) - update to 1:9.20.26-1~deb13u1
bind-doc - update to 9.20.26-150700.3.29.1
bind - update to 9.20.26-150700.3.29.1
bind-debuginfo - update to 9.20.26-150700.3.29.1
bind-utils-debuginfo - update to 9.20.26-150700.3.29.1
bind-debugsource - update to 9.20.26-150700.3.29.1
bind-utils - update to 9.20.26-150700.3.29.1