Denial of Service Vulnerability in BIND Named Service
A memory management flaw in BIND 9 allows an attacker-controlled authoritative DNS server to trigger a service abort by providing a maliciously crafted 65536-byte negative DNS response.
CVE search metadata
CVE search record: CVE-2026-19667. Severity: high. CVSS: 7.5. KEV: no. Product: BIND (9.11.0 - 9.18.50), BIND (9.20.0 - 9.20.27), BIND (9.21.0 - 9.21.25), BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1), BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1), BIND (9.18.0 - 9.18.50), BIND (9.18.11-S1 - 9.18.50-S1), BIND (9.20.9-S1 - 9.20.27-S1), BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1), BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1), BIND (9.20.0 <= version < 9.20.29, 9.21.0 <= version < 9.21.26). Brief: Denial of Service Vulnerability in BIND Named Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bind-dos/
CVE search record: CVE-2026-76163. Severity: high. CVSS: 7.5. KEV: no. Product: BIND (9.11.0 - 9.18.50), BIND (9.20.0 - 9.20.27), BIND (9.21.0 - 9.21.25), BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1), BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1), BIND (9.18.0 - 9.18.50), BIND (9.18.11-S1 - 9.18.50-S1), BIND (9.20.9-S1 - 9.20.27-S1), BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1), BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1), BIND (9.20.0 <= version < 9.20.29, 9.21.0 <= version < 9.21.26). Brief: Denial of Service Vulnerability in BIND Named Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bind-dos/
CVE search record: CVE-2026-19666. Severity: high. CVSS: 7.5. KEV: no. Product: BIND (9.11.0 - 9.18.50), BIND (9.20.0 - 9.20.27), BIND (9.21.0 - 9.21.25), BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1), BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1), BIND (9.18.0 - 9.18.50), BIND (9.18.11-S1 - 9.18.50-S1), BIND (9.20.9-S1 - 9.20.27-S1), BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1), BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1), BIND (9.20.0 <= version < 9.20.29, 9.21.0 <= version < 9.21.26). Brief: Denial of Service Vulnerability in BIND Named Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bind-dos/
CVE search record: CVE-2026-81563. Severity: high. CVSS: 7.5. KEV: no. Product: BIND (9.11.0 - 9.18.50), BIND (9.20.0 - 9.20.27), BIND (9.21.0 - 9.21.25), BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1), BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1), BIND (9.18.0 - 9.18.50), BIND (9.18.11-S1 - 9.18.50-S1), BIND (9.20.9-S1 - 9.20.27-S1), BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1), BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1), BIND (9.20.0 <= version < 9.20.29, 9.21.0 <= version < 9.21.26). Brief: Denial of Service Vulnerability in BIND Named Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bind-dos/
CVE search record: CVE-2026-77692. Severity: high. CVSS: 7.5. KEV: no. Product: BIND (9.11.0 - 9.18.50), BIND (9.20.0 - 9.20.27), BIND (9.21.0 - 9.21.25), BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1), BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1), BIND (9.18.0 - 9.18.50), BIND (9.18.11-S1 - 9.18.50-S1), BIND (9.20.9-S1 - 9.20.27-S1), BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1), BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1), BIND (9.20.0 <= version < 9.20.29, 9.21.0 <= version < 9.21.26). Brief: Denial of Service Vulnerability in BIND Named Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bind-dos/
CVE search record: CVE-2026-81736. Severity: high. CVSS: 7.5. KEV: no. Product: BIND (9.11.0 - 9.18.50), BIND (9.20.0 - 9.20.27), BIND (9.21.0 - 9.21.25), BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1), BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1), BIND (9.18.0 - 9.18.50), BIND (9.18.11-S1 - 9.18.50-S1), BIND (9.20.9-S1 - 9.20.27-S1), BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1), BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1), BIND (9.20.0 <= version < 9.20.29, 9.21.0 <= version < 9.21.26). Brief: Denial of Service Vulnerability in BIND Named Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-bind-dos/
What's new
- 1. added CVE-2026-19666 +4 Sep 17, 13:13 via securityweek
- 2. added coverage for BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1) Sep 16, 17:52 via nvd
- 3. added coverage for BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1) Sep 16, 17:51 via nvd
- 4. added coverage for BIND (9.18.0 - 9.18.50) +4 products Sep 16, 15:50 via nvd
Internet Systems Consortium (ISC) BIND 9 is susceptible to a denial-of-service (DoS) vulnerability, tracked as CVE-2026-19667. The vulnerability occurs when the named process receives a negative DNS response from an authoritative server that is precisely 65536 bytes in size. Under these specific conditions, the software creates a cache entry with a size of zero bytes. Subsequent attempts by the named service to read this invalid entry result in an assertion failure, forcing the process to abort.
This issue affects a wide range of BIND versions, including the 9.11, 9.18, 9.20, and 9.21 branches, as well as their corresponding versions in the BIND Subscription Edition (S1). Given that named is a critical component of DNS infrastructure, a successful trigger of this abort will result in a complete loss of DNS resolution services for systems relying on the affected resolver, necessitating a manual restart of the service and leaving the organization vulnerable until the service is patched.
Impact
The vulnerability results in a high-severity denial-of-service condition affecting the availability of DNS infrastructure. If successfully exploited, the named process crashes, leading to a complete outage of name resolution services for all clients served by the affected BIND instance. Organizations heavily dependent on internal BIND resolvers for network operations may experience widespread service disruption across their environment.
Recommendation
- Patch all vulnerable instances of BIND 9 immediately. Organizations should prioritize updating to the latest vendor-provided release that addresses CVE-2026-19667.
- Implement monitoring to track
namedservice crashes or restarts, which may indicate attempted exploitation or active service degradation. - Review DNS configurations to ensure that the resolver is not configured to trust unverified or suspicious authoritative servers that could be leveraged to deliver the malicious 65536-byte response.
- Ensure all logging for the BIND service is centralized to capture error messages or assertions that occur immediately preceding a service crash.
Mitigations
Upgrade BIND to the latest patched version provided by Internet Systems Consortium
CVE-2026-19667