PT-2026-63414 · Isc+2 · Bind 9+2

CVE-2026-11331

·

Published

2026-07-22

·

Updated

2026-08-19

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.16.0 through 9.18.50 BIND 9 versions 9.20.0 through 9.20.24 BIND 9 versions 9.21.0 through 9.21.23 BIND 9 versions 9.16.8-S1 through 9.18.50-S1 BIND 9 versions 9.20.9-S1 through 9.20.24-S1
Description An attacker can craft query names of sufficient length to trigger a NAMETOOLONG error condition during the processing of Response Policy Zones (RPZ) when wildcard CNAME policies are used. This error is not handled correctly, which may allow the attacker to bypass the RPZ rule or cause the software to exit unexpectedly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54509
ALSA-2026:54510
ALSA-2026:55437
ALSA-2026:55442
AZL-93129
CVE-2026-11331
ECHO-D176-CEDE-4CE1
MGASA-2026-0331
OESA-2026-3289
OESA-2026-3290
OESA-2026-3291
OESA-2026-3331
OPENSUSE-SU-2026:11375-1
OPENSUSE-SU-2026:21489-1
RHSA-2026:54071
SUSE-SU-2026:3426-1
SUSE-SU-2026:3452-1
SUSE-SU-2026:3476-1
SUSE-SU-2026:3477-1
SUSE-SU-2026:3517-1
SUSE-SU-2026:3554-1
USN-8648-1

Affected Products

Bind 9
Rocky Linux
Ubuntu