An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jul 28, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade bind-licenseUpgrade bind-libsUpgrade bindUpgrade bind-libs-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind-debugsourceUpgrade bind-docUpgrade bind-utilsUpgrade bind-develUpgrade bind-utils-debuginfoUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-dnssec-utils | Aug 10, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade bind9 | Jul 28, 2026 | Jul 28, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Sep 9, 2026 | Sep 8, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory31 | Sep 16, 2026 | Sep 16, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Sep 3, 2026 | Jul 22, 2026 |
| Redhat_linux | — | Upgrade bind9.16-libsUpgrade bindUpgrade bind9.16-utilsUpgrade bind-dnssec-utilsUpgrade bind9.18-libs-debuginfoUpgrade bind9.18-libsUpgrade bind-debugsourceUpgrade bind-utilsUpgrade bind-docUpgrade python3-bind9.16Upgrade bind-licenseUpgrade bind9.18Upgrade bind9.16-docUpgrade bind-utils-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.18-dnssec-utilsUpgrade bind9.18-chrootUpgrade bind9.18-utils-debuginfoUpgrade bind9.16-chrootUpgrade bind9.18-develUpgrade bind-debuginfoUpgrade python3-bindUpgrade bind9.18-debuginfoUpgrade bind9.18-docUpgrade bind-libsUpgrade bind9.16-libs-debuginfoUpgrade bind9.16Upgrade bind9.18-dnssec-utils-debuginfoUpgrade bind-develUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-debuginfoUpgrade bind-chrootUpgrade bind9.18-debugsourceUpgrade bind9.18-utilsUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-dnssec-utilsUpgrade bind-dnssec-docUpgrade bind9.16-develUpgrade bind9.16-licenseUpgrade bind9.16-debugsourceUpgrade bind-libs-debuginfo | Jul 24, 2026 | Jul 22, 2026 |
| Rocky_linux | — | Upgrade bind9.16-chrootUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-utilsUpgrade bind9.18-libs-debuginfoUpgrade bindUpgrade bind-libsUpgrade bind-debugsourceUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-libsUpgrade bind9.18-utilsUpgrade bind-dnssec-utilsUpgrade bind9.18-develUpgrade bind9.18-libsUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.18Upgrade bind-libs-debuginfoUpgrade bind9.16-debuginfoUpgrade bind9.18-dnssec-utils-debuginfoUpgrade bind9.18-debugsourceUpgrade bind-chrootUpgrade bind9.16Upgrade bind9.18-dnssec-utilsUpgrade bind9.16-libs-debuginfoUpgrade bind9.16-develUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-debugsourceUpgrade bind-develUpgrade bind-debuginfoUpgrade bind-utils-debuginfoUpgrade bind9.18-debuginfoUpgrade bind-utilsUpgrade bind9.18-chrootUpgrade bind9.18-utils-debuginfo | Aug 17, 2026 | Aug 14, 2026 |
| Ubuntu | — | Upgrade bind9 | Aug 19, 2026 | Aug 19, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 17, 2026 | Jul 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub