{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/bind-9-9.16.8-s1-through-9.18.50-s1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-11331"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIND 9 (9.16.0 through 9.18.50)","BIND 9 (9.20.0 through 9.20.24)","BIND 9 (9.21.0 through 9.21.23)","BIND 9 (9.16.8-S1 through 9.18.50-S1)","BIND 9 (9.20.9-S1 through 9.20.24-S1)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","denial-of-service","dns","bind","networking"],"_cs_type":"advisory","_cs_vendors":["ISC"],"content_html":"\u003cp\u003eCVE-2026-11331 describes a significant vulnerability in multiple versions of ISC BIND 9, a widely used DNS software. This flaw specifically impacts BIND 9 resolvers configured with Response Policy Zones (RPZ) that utilize wildcard CNAME policies. An attacker, by discerning or guessing this configuration, can intentionally craft DNS query names of excessive length. This action triggers a \u0026quot;NAMETOOLONG\u0026quot; error condition during BIND 9's RPZ processing. Crucially, the software does not handle this error condition gracefully, which can lead to two critical outcomes: the successful bypass of the configured RPZ rules, allowing access to domains that should be blocked, or an unexpected termination of the BIND 9 process itself, resulting in a denial of service (DoS) for DNS resolution. The affected versions span from 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and specific \u0026quot;S1\u0026quot; branches.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a target DNS resolver running a vulnerable version of BIND 9 and determines or infers that it utilizes RPZ with wildcard CNAME policies.\u003c/li\u003e\n\u003cli\u003eThe attacker constructs a specialized DNS query containing an unusually long query name.\u003c/li\u003e\n\u003cli\u003eThe crafted query name is engineered to exceed the internal buffer or processing limits within BIND 9's RPZ component.\u003c/li\u003e\n\u003cli\u003eThe vulnerable BIND 9 instance receives the malicious query and attempts to process the long query name against its configured RPZ rules.\u003c/li\u003e\n\u003cli\u003eDuring this RPZ processing, the excessive length of the query name triggers an internal \u0026quot;NAMETOOLONG\u0026quot; error condition within BIND 9.\u003c/li\u003e\n\u003cli\u003eDue to the improper handling of this specific error, the BIND 9 resolver fails to correctly enforce the RPZ rule.\u003c/li\u003e\n\u003cli\u003eThis mishandling results in either the bypass of the intended RPZ rule, allowing the attacker to resolve a domain that should have been blocked, or causes the BIND 9 process to terminate unexpectedly.\u003c/li\u003e\n\u003cli\u003eIf the BIND 9 process terminates, it leads to a denial-of-service condition, impacting DNS resolution for clients relying on that server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe primary impacts of successful exploitation of CVE-2026-11331 are the circumvention of security policies and service disruption. If an attacker bypasses Response Policy Zone (RPZ) rules, they can access or direct users to malicious domains that were intended to be blocked, thereby undermining the organization's network security posture. Alternatively, the vulnerability can lead to an unexpected termination of the BIND 9 software, causing a denial of service. This can severely disrupt DNS resolution services for an organization, rendering internal and external services inaccessible, and impacting operational continuity. The CVSS v3.1 Base Score of 7.5 indicates a high severity threat, primarily due to the high availability impact and moderate integrity impact (through RPZ bypass).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-11331 by upgrading all affected BIND 9 instances to a fixed version immediately.\u003c/li\u003e\n\u003cli\u003eMonitor BIND 9 logs for \u003ccode\u003eNAMETOOLONG\u003c/code\u003e error messages, especially those occurring during RPZ processing.\u003c/li\u003e\n\u003cli\u003eImplement proactive monitoring for unexpected termination or restarts of the BIND 9 process, as this may indicate a denial-of-service attack or critical error condition.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T15:19:04Z","date_published":"2026-07-22T15:19:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-11331-bind9-rpz-bypass-dos/","summary":"An attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.","title":"CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-11331-bind9-rpz-bypass-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - BIND 9 (9.16.8-S1 Through 9.18.50-S1)","version":"https://jsonfeed.org/version/1.1"}