Input validation error in ISC BIND - CVE-2026-80274
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of a NOQNAME proof in the BIND validating resolver when processing DNSSEC responses. A remote attacker can send a DNS response containing a valid wildcard answer and signed NSEC3 proof followed by an unsigned NSEC record at the same owner name to cause a denial of service.
The resolver must query a DNSSEC-signed authoritative zone.
Affected software
Debian Linux
bind9 (Debian package)
How to mitigate CVE-2026-80274
bind9 (Debian package) - update to 1:9.20.29-1~deb13u1