{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/isc/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-11622"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIND 9 (9.11.0 through 9.18.50)","BIND 9 (9.20.0 through 9.20.24)","BIND 9 (9.21.0 through 9.21.23)","BIND 9 (9.11.3-S1 through 9.18.50-S1)","BIND 9 (9.20.9-S1 through 9.20.24-S1)"],"_cs_severities":["high"],"_cs_tags":["dns","denial-of-service","vulnerability","isc","bind","cache-poisoning","network"],"_cs_type":"advisory","_cs_vendors":["ISC"],"content_html":"\u003cp\u003eCVE-2026-11622 details a critical vulnerability affecting multiple versions of ISC BIND 9, a widely used DNS software. This flaw impacts DNSSEC validating resolvers, allowing an unauthenticated attacker to trigger a denial-of-service (DoS) condition. The attack involves initiating a \u0026quot;random subdomain attack\u0026quot; against a DNSSEC-signed zone. By sending a high volume of queries for non-existent, random subdomains, the attacker can force the resolver to consume excessive memory. The vulnerability specifically targets BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and their respective S1 branches (9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1). This uncontrolled memory growth can occur even when \u003ccode\u003emax-cache-size\u003c/code\u003e limits are configured, rendering the resolver unresponsive and disrupting critical DNS resolution services.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a target BIND 9 DNSSEC validating resolver and a DNSSEC-signed zone that the resolver can query.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates a flood of DNS queries for non-existent, random subdomains (e.g., \u003ccode\u003erandomstring.example.com\u003c/code\u003e) within the chosen DNSSEC-signed zone.\u003c/li\u003e\n\u003cli\u003eThe vulnerable BIND 9 resolver attempts to validate each unique non-existent subdomain query, a process that is computationally intensive for DNSSEC.\u003c/li\u003e\n\u003cli\u003eThe rate at which the attacker sends queries for new, random subdomains exceeds the resolver's capacity to complete DNSSEC validation for each request.\u003c/li\u003e\n\u003cli\u003eAs the resolver's cache attempts to store validation states for numerous unique, non-existent entries, its memory usage begins to increase rapidly.\u003c/li\u003e\n\u003cli\u003eThe memory consumption escalates significantly, potentially by orders of magnitude beyond any configured \u003ccode\u003emax-cache-size\u003c/code\u003e parameter due to the nature of DNSSEC validation state storage.\u003c/li\u003e\n\u003cli\u003eThe BIND 9 process exhausts available memory resources, leading to a crash or severe performance degradation, effectively causing a denial-of-service condition for all DNS queries.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-11622 leads to a complete denial-of-service for affected BIND 9 DNSSEC validating resolvers. This means that organizations relying on these resolvers will experience service outages for DNS resolution, preventing access to internal and external resources that depend on DNS. The impact can be severe for internet service providers, enterprises, and other entities running vulnerable BIND instances, causing widespread network disruptions and unavailability of critical applications. The memory exhaustion can persist even with cache size limits, making manual intervention necessary to restore service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-11622 on all affected BIND 9 instances immediately by upgrading to a version where the vulnerability is resolved. Consult ISC advisories for specific patched versions.\u003c/li\u003e\n\u003cli\u003eMonitor DNS server resource utilization (CPU, memory, network I/O) for anomalies. Sudden spikes in memory usage on BIND 9 servers could indicate an attempted or ongoing exploitation of CVE-2026-11622.\u003c/li\u003e\n\u003cli\u003eImplement rate limiting on incoming DNS queries where feasible to mitigate the impact of high-volume attacks, though this may not fully prevent memory exhaustion for CVE-2026-11622.\u003c/li\u003e\n\u003cli\u003eReview DNS query logs for unusual patterns, such as a high volume of queries for random, non-existent subdomains from a single source or a small set of sources, which could indicate a random subdomain attack.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T15:22:02Z","date_published":"2026-07-22T15:20:51Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-11622-dnssec-memory-dos/","summary":"A DNSSEC validating resolver, specifically BIND 9 versions within the ranges 9.11.0-9.18.50, 9.20.0-9.20.24, 9.21.0-9.21.23, and their S1 variants, is vulnerable to a denial-of-service attack where an attacker can launch a random subdomain attack against a DNSSEC-signed zone by sending queries faster than the resolver can perform validation, leading to runaway memory usage and potentially exceeding configured limits by orders of magnitude.","title":"CVE-2026-11622: BIND 9 DNSSEC Resolver Memory Exhaustion Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-11622-dnssec-memory-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Isc","version":"https://jsonfeed.org/version/1.1"}