Insufficient verification of data authenticity in ISC BIND - CVE-2026-77119
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause DNS cache poisoning.
The vulnerability exists due to insufficient verification of data authenticity in BIND 9 NSEC3 insecure-referral proof validation when processing insecure-referral proofs. A remote attacker can provide a validly signed NSEC3 record from an unrelated sibling zone to cause DNS cache poisoning.
Affected software
Debian Linux
bind9 (Debian package)
How to mitigate CVE-2026-77119
bind9 (Debian package) - update to 1:9.20.29-1~deb13u1