Resource exhaustion in ISC BIND - CVE-2026-11605

 

Resource exhaustion in ISC BIND - CVE-2026-11605

Published: July 23, 2026


Vulnerability identifier: #VU139211
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11605
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to resource exhaustion in DNSSEC validation when processing answers containing many valid but superfluous RRSIG records. A remote attacker can send a query that triggers validation of such records to cause a denial of service.

The issue results in disproportionate CPU consumption during validation.


Affected software

ISC BIND
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
Ubuntu
openEuler
bind9 (Ubuntu package)
bind-debugsource
bind-license
bind-dnssec-doc
bind-utils
bind-libs
bind-dnssec-utils
bind-devel
bind-debuginfo
bind-chroot
bind
bind9 (Debian package)
bind-doc
bind-utils-debuginfo

How to mitigate CVE-2026-11605

Install security update from vendor's website.

ISC BIND - addressed in versions 9.20.26, 9.20.26-s1, 9.21.24
bind9 (Ubuntu package) - addressed in versions 1:9.18.39-0ubuntu0.22.04.5, 1:9.18.39-0ubuntu0.24.04.6, 1:9.20.24-1ubuntu0.2
bind-debugsource - update to 9.20.21-4
bind-license - update to 9.20.21-4
bind-dnssec-doc - update to 9.20.21-4
bind-utils - update to 9.20.21-4
bind-libs - update to 9.20.21-4
bind-dnssec-utils - update to 9.20.21-4
bind-devel - update to 9.20.21-4
bind-debuginfo - update to 9.20.21-4
bind-chroot - update to 9.20.21-4
bind - update to 9.20.21-4
bind9 (Debian package) - update to 1:9.20.26-1~deb13u1
bind-doc - update to 9.20.26-150700.3.29.1
bind - update to 9.20.26-150700.3.29.1
bind-debuginfo - update to 9.20.26-150700.3.29.1
bind-utils-debuginfo - update to 9.20.26-150700.3.29.1
bind-debugsource - update to 9.20.26-150700.3.29.1
bind-utils - update to 9.20.26-150700.3.29.1

External References

Related Security Bulletins