Input validation error in ISC BIND - CVE-2026-10822
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in DNS record text rendering when processing a stored DNS record with a PRIVATEDNS algorithm identifier length longer than the actual identifier data. A remote attacker can supply a specially crafted DNS record to cause a denial of service.
User interaction is required for BIND to later render the stored record to text.