<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>BIND (9.11.3-S1-9.18.50-S1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/bind-9.11.3-s1-9.18.50-s1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 15:51:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/bind-9.11.3-s1-9.18.50-s1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>BIND 9 Denial of Service via Malformed DNS64 Response</title><link>https://feed.craftedsignal.io/briefs/2026-09-bind-dns64-dos/</link><pubDate>Wed, 16 Sep 2026 15:51:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-bind-dns64-dos/</guid><description>A vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.</description><content:encoded><![CDATA[<p>The Internet Systems Consortium (ISC) BIND 9 software contains a vulnerability (CVE-2026-19666) that affects resolvers specifically configured to utilize the DNS64 function. When the resolver receives a maliciously crafted or malformed response from an authoritative DNS server, the <code>named</code> process encounters an unhandled state, causing the service to exit unexpectedly. This leads to a denial of service (DoS) for all clients relying on the affected resolver. The vulnerability impacts a wide range of BIND 9 versions, including the 9.11, 9.20, and 9.21 branches, as well as their subscription versions. Because this requires an authoritative server to provide specific malformed data, the scope of risk is primarily limited to environments where the resolver configuration allows for such upstream responses, or where an attacker can influence the traffic returned to the recursive resolver.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the immediate termination of the <code>named</code> process. In production environments, this causes a complete outage of DNS resolution services for the affected infrastructure, preventing internal and external network communication dependent on name resolution.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching affected BIND 9 instances to the latest secure version provided by ISC. Because this is a crash-inducing vulnerability, monitor DNS server logs for unexpected service restarts or frequent <code>named</code> process terminations. Review configuration files to identify if <code>dns64</code> is enabled, as this is a prerequisite for the vulnerability.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>network-infrastructure</category><category>vulnerability</category><category>dns</category><category>infrastructure</category></item></channel></rss>