Resource exhaustion in ISC BIND - CVE-2026-75029
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of duplicate singleton RDATA records in the named message parser when processing query responses. A remote attacker can send a query response containing multiple identical copies of a record that should exist only once to cause a denial of service.
Affected software
Debian Linux
bind9 (Debian package)
How to mitigate CVE-2026-75029
bind9 (Debian package) - update to 1:9.20.29-1~deb13u1