ISC Patches 14 Vulnerabilities in BIND 9 Security Update

https://www.securityweek.com/wp-content/uploads/2024/02/DNS.jpeg

Internet Systems Consortium (ISC) has released fresh security updates for BIND, the widely used open source DNS server software, resolving 14 vulnerabilities that could lead to denial-of-service (DoS) attacks.

Seven are high-severity flaws that could be exploited to cause an unexpected program exit, memory exhaustion, named termination, and resource exhaustion, causing DoS conditions.

The remotely exploitable bugs are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736.

They can be triggered using mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers from the authoritative server, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and negative answers of 65,536 bytes.

CVE-2026-77692 stands out because it can be exploited remotely without authentication to crash named with a single DoH SIG(0) request.

“An attacker can cause named to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely,” ISC explains.

Advertisement. Scroll to continue...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more