<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>BIND (9.18.11-S1 - 9.18.50-S1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/bind-9.18.11-s1---9.18.50-s1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 15:50:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/bind-9.18.11-s1---9.18.50-s1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in BIND Named Service</title><link>https://feed.craftedsignal.io/briefs/2026-09-bind-dos/</link><pubDate>Wed, 16 Sep 2026 15:50:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-bind-dos/</guid><description>A memory management flaw in BIND 9 allows an attacker-controlled authoritative DNS server to trigger a service abort by providing a maliciously crafted 65536-byte negative DNS response.</description><content:encoded><![CDATA[<p>Internet Systems Consortium (ISC) BIND 9 is susceptible to a denial-of-service (DoS) vulnerability, tracked as CVE-2026-19667. The vulnerability occurs when the <code>named</code> process receives a negative DNS response from an authoritative server that is precisely 65536 bytes in size. Under these specific conditions, the software creates a cache entry with a size of zero bytes. Subsequent attempts by the <code>named</code> service to read this invalid entry result in an assertion failure, forcing the process to abort.</p>
<p>This issue affects a wide range of BIND versions, including the 9.11, 9.18, 9.20, and 9.21 branches, as well as their corresponding versions in the BIND Subscription Edition (S1). Given that <code>named</code> is a critical component of DNS infrastructure, a successful trigger of this abort will result in a complete loss of DNS resolution services for systems relying on the affected resolver, necessitating a manual restart of the service and leaving the organization vulnerable until the service is patched.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a high-severity denial-of-service condition affecting the availability of DNS infrastructure. If successfully exploited, the <code>named</code> process crashes, leading to a complete outage of name resolution services for all clients served by the affected BIND instance. Organizations heavily dependent on internal BIND resolvers for network operations may experience widespread service disruption across their environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch all vulnerable instances of BIND 9 immediately. Organizations should prioritize updating to the latest vendor-provided release that addresses CVE-2026-19667.</li>
<li>Implement monitoring to track <code>named</code> service crashes or restarts, which may indicate attempted exploitation or active service degradation.</li>
<li>Review DNS configurations to ensure that the resolver is not configured to trust unverified or suspicious authoritative servers that could be leveraged to deliver the malicious 65536-byte response.</li>
<li>Ensure all logging for the BIND service is centralized to capture error messages or assertions that occur immediately preceding a service crash.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>dns</category><category>infrastructure</category></item></channel></rss>