{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bind-9.20.0--version--9.20.29-9.21.0--version--9.21.26/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:isc:bind:9.11.0:*:*:*:*:*:*:*","cpe:2.3:a:isc:bind:9.18.50:*:*:*:*:*:*:*","cpe:2.3:a:isc:bind:9.20.27:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-19667"},{"cvss":7.5,"id":"CVE-2026-76163"},{"cvss":7.5,"id":"CVE-2026-19666"},{"cvss":7.5,"id":"CVE-2026-81563"},{"cvss":7.5,"id":"CVE-2026-77692"},{"cvss":7.5,"id":"CVE-2026-81736"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIND (9.11.0 - 9.18.50)","BIND (9.20.0 - 9.20.27)","BIND (9.21.0 - 9.21.25)","BIND Subscription Edition (9.11.3-S1 - 9.18.50-S1)","BIND Subscription Edition (9.20.9-S1 - 9.20.27-S1)","BIND (9.18.0 - 9.18.50)","BIND (9.18.11-S1 - 9.18.50-S1)","BIND (9.20.9-S1 - 9.20.27-S1)","BIND (9.20.0-9.20.27, 9.21.0-9.21.25, 9.20.9-S1-9.20.27-S1)","BIND (9.11.0 - 9.18.50, 9.20.0 - 9.20.27, 9.21.0 - 9.21.25, 9.11.3-S1 - 9.18.50-S1, 9.20.9-S1 - 9.20.27-S1)","BIND (9.20.0 \u003c= version \u003c 9.20.29, 9.21.0 \u003c= version \u003c 9.21.26)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","dns","infrastructure"],"_cs_type":"advisory","_cs_vendors":["Internet Systems Consortium"],"content_html":"\u003cp\u003eInternet Systems Consortium (ISC) BIND 9 is susceptible to a denial-of-service (DoS) vulnerability, tracked as CVE-2026-19667. The vulnerability occurs when the \u003ccode\u003enamed\u003c/code\u003e process receives a negative DNS response from an authoritative server that is precisely 65536 bytes in size. Under these specific conditions, the software creates a cache entry with a size of zero bytes. Subsequent attempts by the \u003ccode\u003enamed\u003c/code\u003e service to read this invalid entry result in an assertion failure, forcing the process to abort.\u003c/p\u003e\n\u003cp\u003eThis issue affects a wide range of BIND versions, including the 9.11, 9.18, 9.20, and 9.21 branches, as well as their corresponding versions in the BIND Subscription Edition (S1). Given that \u003ccode\u003enamed\u003c/code\u003e is a critical component of DNS infrastructure, a successful trigger of this abort will result in a complete loss of DNS resolution services for systems relying on the affected resolver, necessitating a manual restart of the service and leaving the organization vulnerable until the service is patched.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a high-severity denial-of-service condition affecting the availability of DNS infrastructure. If successfully exploited, the \u003ccode\u003enamed\u003c/code\u003e process crashes, leading to a complete outage of name resolution services for all clients served by the affected BIND instance. Organizations heavily dependent on internal BIND resolvers for network operations may experience widespread service disruption across their environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch all vulnerable instances of BIND 9 immediately. Organizations should prioritize updating to the latest vendor-provided release that addresses CVE-2026-19667.\u003c/li\u003e\n\u003cli\u003eImplement monitoring to track \u003ccode\u003enamed\u003c/code\u003e service crashes or restarts, which may indicate attempted exploitation or active service degradation.\u003c/li\u003e\n\u003cli\u003eReview DNS configurations to ensure that the resolver is not configured to trust unverified or suspicious authoritative servers that could be leveraged to deliver the malicious 65536-byte response.\u003c/li\u003e\n\u003cli\u003eEnsure all logging for the BIND service is centralized to capture error messages or assertions that occur immediately preceding a service crash.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-17T13:13:20Z","date_published":"2026-09-16T15:50:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bind-dos/","summary":"A memory management flaw in BIND 9 allows an attacker-controlled authoritative DNS server to trigger a service abort by providing a maliciously crafted 65536-byte negative DNS response.","title":"Denial of Service Vulnerability in BIND Named Service","url":"https://feed.craftedsignal.io/briefs/2026-09-bind-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - BIND (9.20.0 \u003c= Version \u003c 9.20.29, 9.21.0 \u003c= Version \u003c 9.21.26)","version":"https://jsonfeed.org/version/1.1"}