The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jul 28, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade bind-dnssec-utils-debuginfoUpgrade bind-libs-debuginfoUpgrade bindUpgrade bind-licenseUpgrade bind-docUpgrade bind-libsUpgrade bind-chrootUpgrade bind-dnssec-utilsUpgrade bind-develUpgrade bind-utils-debuginfoUpgrade bind-debuginfoUpgrade bind-debugsourceUpgrade bind-utils | Aug 10, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade bind9 | Jul 28, 2026 | Jul 28, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Sep 3, 2026 | Sep 2, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory31 | Sep 16, 2026 | Sep 16, 2026 |
| Redhat_linux | — | — | Jul 24, 2026 | Jul 22, 2026 |
| Ubuntu | — | Upgrade bind9 | Aug 19, 2026 | Aug 19, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 17, 2026 | Jul 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub