Memory leak in ISC BIND - CVE-2026-81563
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a failure to properly deallocate internal resources in SVCB/HTTPS AliasMode additional-data processing when processing an SVCB/HTTPS AliasMode record that references 14 or more SVCB/HTTPS ServiceMode records. A remote attacker can cause the resolver to process such records to cause a denial of service.
Repeated exploitation is required to exhaust resources.
Affected software
Debian Linux
bind9 (Debian package)
How to mitigate CVE-2026-81563
bind9 (Debian package) - update to 1:9.20.29-1~deb13u1