BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | May 25, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade bind-export-develUpgrade bind-libsUpgrade bind-pkcs11-develUpgrade bind-pkcs11Upgrade bind-licenseUpgrade bindUpgrade bind-develUpgrade bind-sdbUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bind-sdb-chrootUpgrade bind-lite-develUpgrade bind-export-libsUpgrade bind-pkcs11-utilsUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-utils | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade bind-dnssec-utils-debuginfoUpgrade bind-dnssec-utilsUpgrade bind-licenseUpgrade bindUpgrade bind-utils-debuginfoUpgrade bind-debugsourceUpgrade bind-docUpgrade bind-libs-debuginfoUpgrade bind-debuginfoUpgrade bind-utilsUpgrade bind-develUpgrade bind-chrootUpgrade bind-libs | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade bind9 | May 24, 2026 | May 24, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory30 | Jun 29, 2026 | Jun 29, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 26, 2026 |
| Suse | — | Upgrade bind-modules-perlUpgrade libisc1107-32bitUpgrade libisccfg163Upgrade bind-docUpgrade bind-utilsUpgrade libdns1110Upgrade libirs161Upgrade libbind9-161Upgrade libisccfg1600Upgrade python-bindUpgrade libisccc161Upgrade python3-bindUpgrade libirs1601Upgrade libdns1605Upgrade libisc1606Upgrade bind-modules-mysqlUpgrade bind-modules-bdbhptUpgrade libisc1107Upgrade bind-modules-sqlite3Upgrade bind-modules-genericUpgrade bind-chrootenvUpgrade bindUpgrade bind-modules-ldapUpgrade libirs-develUpgrade bind-develUpgrade liblwres161 | Jun 9, 2026 | Jun 5, 2026 |
| Ubuntu | — | Upgrade bind9 (Ubuntu Pro)Upgrade bind9 | May 25, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub