{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/bind-9-9.18.11-s1-through-9.18.50-s1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-12617"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIND 9 (9.18.0 through 9.18.50)","BIND 9 (9.20.0 through 9.20.24)","BIND 9 (9.18.11-S1 through 9.18.50-S1)","BIND 9 (9.20.9-S1 through 9.20.24-S1)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","dns","bind","linux"],"_cs_type":"advisory","_cs_vendors":["ISC"],"content_html":"\u003cp\u003eCVE-2026-12617 describes a denial-of-service (DoS) vulnerability impacting the \u003ccode\u003enamed\u003c/code\u003e resolver in various versions of BIND 9. This critical issue stems from how the \u003ccode\u003enamed\u003c/code\u003e process handles specific, delayed, or out-of-order DNS responses, particularly for CNAME, DNAME, and A records. An attacker, by controlling or compromising an authoritative DNS server, can craft a scenario where a client queries for certain record types (e.g., DNAME and an A record below it, or a CNAME and an A record for the same name). If the authoritative server then delivers a positive A record response but delays and subsequently provides a negative DNAME response or a self-referential CNAME response, the \u003ccode\u003enamed\u003c/code\u003e process can terminate unexpectedly. This vulnerability affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, and specific S1 versions, leading to a disruption of DNS resolution services.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA client system initiates DNS queries to a vulnerable BIND 9 \u003ccode\u003enamed\u003c/code\u003e resolver.\u003c/li\u003e\n\u003cli\u003eThe client's query specifically requests a DNAME record and an A record located hierarchically below that DNAME, or requests a CNAME record and an A record for the same name.\u003c/li\u003e\n\u003cli\u003eA malicious or compromised authoritative DNS server intercepts these queries or is the designated authority.\u003c/li\u003e\n\u003cli\u003eThe malicious authoritative server immediately responds to the A record query with a positive resolution.\u003c/li\u003e\n\u003cli\u003eConcurrently, the authoritative server intentionally delays its response to the DNAME or CNAME query.\u003c/li\u003e\n\u003cli\u003eAfter a delay, the authoritative server sends a negative response for the DNAME query or a self-referential CNAME response for the CNAME query.\u003c/li\u003e\n\u003cli\u003eThe vulnerable BIND 9 \u003ccode\u003enamed\u003c/code\u003e resolver, processing these out-of-order or specific responses, encounters an unexpected internal state.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003enamed\u003c/code\u003e process terminates abruptly, resulting in a denial of service for DNS resolution services provided by that instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12617 leads directly to a denial of service (DoS) for the affected BIND 9 \u003ccode\u003enamed\u003c/code\u003e resolver. When the \u003ccode\u003enamed\u003c/code\u003e process terminates unexpectedly, it ceases to resolve DNS queries, rendering any services relying on that DNS server unreachable. This can disrupt critical network functions, internal and external website access, email delivery, and any other system dependent on DNS resolution. The impact can range from temporary outages to prolonged service interruptions depending on the organization's DNS infrastructure and recovery procedures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-12617 immediately by upgrading all affected BIND 9 installations to the patched versions provided by ISC.\u003c/li\u003e\n\u003cli\u003eMonitor DNS server health and process uptime for \u003ccode\u003enamed\u003c/code\u003e using host-level monitoring tools (e.g., \u003ccode\u003esystemd\u003c/code\u003e, \u003ccode\u003emonit\u003c/code\u003e, \u003ccode\u003enagios\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eImplement robust logging for DNS query and response anomalies to potentially identify unusual response patterns that could precede or indicate exploitation attempts of CVE-2026-12617.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T15:22:33Z","date_published":"2026-07-22T15:22:33Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-12617-bind-dos/","summary":"This vulnerability affects BIND 9 resolver (`named`) and can lead to unexpected program termination (denial of service). The issue occurs when the resolver receives specific, delayed, or out-of-order responses to queries for CNAME or DNAME and A records. Specifically, if an authoritative server delays a DNAME or self-referential CNAME response while providing an A record, the `named` process may crash.","title":"CVE-2026-12617: BIND 9 Denial of Service via Malicious DNS Responses","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-12617-bind-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - BIND 9 (9.18.11-S1 Through 9.18.50-S1)","version":"https://jsonfeed.org/version/1.1"}