BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | May 25, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade bind-lite-develUpgrade bind-sdbUpgrade bind-sdb-chrootUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-utilsUpgrade bind-export-libsUpgrade bind-develUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-export-develUpgrade bind-libsUpgrade bind-pkcs11-develUpgrade bind-licenseUpgrade bindUpgrade bind-pkcs11 | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade bindUpgrade bind-dnssec-utilsUpgrade bind-libs-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind-docUpgrade bind-licenseUpgrade bind-debugsourceUpgrade bind-debuginfoUpgrade bind-libsUpgrade bind-utilsUpgrade bind-develUpgrade bind-chroot | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade bind9 | May 24, 2026 | May 24, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory30 | Jun 29, 2026 | Jun 29, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 26, 2026 |
| Suse | — | Upgrade bind-develUpgrade bind-modules-sqlite3Upgrade bind-modules-ldapUpgrade bind-modules-genericUpgrade bindUpgrade bind-chrootenvUpgrade libirs-develUpgrade liblwres161Upgrade libisc1107Upgrade libisc1107-32bitUpgrade bind-modules-bdbhptUpgrade libisc1606Upgrade libdns1110Upgrade python-bindUpgrade bind-modules-mysqlUpgrade bind-modules-perlUpgrade libisccfg163Upgrade libirs1601Upgrade libbind9-161Upgrade bind-docUpgrade bind-utilsUpgrade python3-bindUpgrade libisccc161Upgrade libisccfg1600Upgrade libirs161Upgrade libdns1605 | Jun 9, 2026 | Jun 5, 2026 |
| Ubuntu | — | Upgrade bind9Upgrade bind9 (Ubuntu Pro) | May 25, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub