It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jul 28, 2026 | Jul 22, 2026 |
| Amazon Linux Ami 2 | — | Upgrade bind-pkcs11Upgrade bind-libsUpgrade bindUpgrade bind-debuginfoUpgrade bind-develUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-sdb-chrootUpgrade bind-export-develUpgrade bind-chrootUpgrade bind-pkcs11-develUpgrade bind-export-libs | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade bind-utilsUpgrade bind-debuginfoUpgrade bind-docUpgrade bind-chrootUpgrade bind-libsUpgrade bind-dnssec-utils-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-debugsourceUpgrade bindUpgrade bind-licenseUpgrade bind-develUpgrade bind-dnssec-utilsUpgrade bind-libs-debuginfo | Aug 10, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade bind9 | Jul 28, 2026 | Jul 28, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory31 | Sep 16, 2026 | Sep 16, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 26, 2026 | Jul 22, 2026 |
| Redhat_linux | — | Upgrade bind9.18-libsUpgrade bind9.16-develUpgrade bind-docUpgrade bind-sdbUpgrade bind9.16-dnssec-utilsUpgrade python3-bind9.16Upgrade bind-utils-debuginfoUpgrade bind-pkcs11-develUpgrade bind-export-libsUpgrade bind9.18-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind9.16-docUpgrade bind-export-develUpgrade bind9.16-utilsUpgrade bind-debugsourceUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-lite-develUpgrade bind9.16-libsUpgrade bind-libs-lite-debuginfoUpgrade bindUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.18-chrootUpgrade bind-dnssec-utilsUpgrade bind-chrootUpgrade bind-licenseUpgrade bind9.18-develUpgrade bind9.16-licenseUpgrade bind-pkcs11-libsUpgrade bind9.16-libs-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-export-libs-debuginfoUpgrade bind9.18-utilsUpgrade bind9.18-dnssec-utilsUpgrade bind9.16-debugsourceUpgrade bind9.18-debugsourceUpgrade bind9.18Upgrade bind9.16-dnssec-utils-debuginfoUpgrade bind-develUpgrade bind-debuginfoUpgrade bind9.18-docUpgrade bind9.16-utils-debuginfoUpgrade bind-libsUpgrade bind9.18-libs-debuginfoUpgrade bind-libs-debuginfoUpgrade python3-bindUpgrade bind9.16-chrootUpgrade bind-dnssec-docNo solution existsUpgrade bind-utilsUpgrade bind-sdb-debuginfoUpgrade bind9.18-dnssec-utils-debuginfoUpgrade bind9.16Upgrade bind-libs-liteUpgrade bind9.18-utils-debuginfoUpgrade bind9.16-debuginfoUpgrade bind-sdb-chrootUpgrade bind-pkcs11 | Jul 24, 2026 | Jul 22, 2026 |
| Rocky_linux | — | Upgrade bind-dnssec-utilsUpgrade bind-sdb-debuginfoUpgrade bind9.16-libs-debuginfoUpgrade bind-libs-debuginfoUpgrade bind9.16Upgrade bind9.16-dnssec-utilsUpgrade bind9.18-debugsourceUpgrade bind9.18-utilsUpgrade bind-develUpgrade bind9.16-utilsUpgrade bind-sdb-chrootUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-develUpgrade bind-export-libs-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.18Upgrade bind9.16-debuginfoUpgrade bind9.16-debugsourceUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.18-utils-debuginfoUpgrade bind9.18-dnssec-utilsUpgrade bind9.18-develUpgrade bind-pkcs11-debuginfoUpgrade bind9.16-libsUpgrade bind-libsUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11Upgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-chrootUpgrade bind9.18-dnssec-utils-debuginfoUpgrade bind9.16-develUpgrade bind-utilsUpgrade bind9.18-libs-debuginfoUpgrade bind-export-develUpgrade bind9.18-chrootUpgrade bind9.18-debuginfoUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-chrootUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind9.18-libsUpgrade bind-debuginfoUpgrade bind-debugsourceUpgrade bindUpgrade bind-export-libsUpgrade bind-utils-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-sdb | Aug 17, 2026 | Aug 15, 2026 |
| Ubuntu | — | Upgrade bind9 | Aug 19, 2026 | Aug 19, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 17, 2026 | Jul 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub