Numeric Truncation Error in ISC BIND - CVE-2026-19667
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to numeric truncation in dns_ncache_add() when processing a negative answer exactly 65536 bytes long from an attacker-controlled authoritative server. A remote attacker can return such a negative answer to cause a denial of service.
Affected software
Debian Linux
bind9 (Debian package)
How to mitigate CVE-2026-19667
bind9 (Debian package) - update to 1:9.20.29-1~deb13u1