{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bind-9.11.0-9.18.50/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-19666"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIND (9.11.0-9.18.50)","BIND (9.20.0-9.20.27)","BIND (9.21.0-9.21.25)","BIND (9.11.3-S1-9.18.50-S1)","BIND (9.20.9-S1-9.20.27-S1)","BIND (9.18.0-9.18.50, 9.20.0-9.20.27, 9.21.0-9.21.25, 9.18.11-S1-9.18.50-S1, 9.20.9-S1-9.20.27-S1)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","network-infrastructure","vulnerability","dns","infrastructure"],"_cs_type":"advisory","_cs_vendors":["ISC"],"content_html":"\u003cp\u003eThe Internet Systems Consortium (ISC) BIND 9 software contains a vulnerability (CVE-2026-19666) that affects resolvers specifically configured to utilize the DNS64 function. When the resolver receives a maliciously crafted or malformed response from an authoritative DNS server, the \u003ccode\u003enamed\u003c/code\u003e process encounters an unhandled state, causing the service to exit unexpectedly. This leads to a denial of service (DoS) for all clients relying on the affected resolver. The vulnerability impacts a wide range of BIND 9 versions, including the 9.11, 9.20, and 9.21 branches, as well as their subscription versions. Because this requires an authoritative server to provide specific malformed data, the scope of risk is primarily limited to environments where the resolver configuration allows for such upstream responses, or where an attacker can influence the traffic returned to the recursive resolver.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate termination of the \u003ccode\u003enamed\u003c/code\u003e process. In production environments, this causes a complete outage of DNS resolution services for the affected infrastructure, preventing internal and external network communication dependent on name resolution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching affected BIND 9 instances to the latest secure version provided by ISC. Because this is a crash-inducing vulnerability, monitor DNS server logs for unexpected service restarts or frequent \u003ccode\u003enamed\u003c/code\u003e process terminations. Review configuration files to identify if \u003ccode\u003edns64\u003c/code\u003e is enabled, as this is a prerequisite for the vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-16T19:51:35Z","date_published":"2026-09-16T15:51:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bind-dns64-dos/","summary":"A vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.","title":"BIND 9 Denial of Service via Malformed DNS64 Response","url":"https://feed.craftedsignal.io/briefs/2026-09-bind-dns64-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - BIND (9.11.0-9.18.50)","version":"https://jsonfeed.org/version/1.1"}