PT-2026-63418 · Isc+1 · Bind 9+1

CVE-2026-12617

·

Published

2026-07-22

·

Updated

2026-08-19

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.18.0 through 9.18.50 BIND 9 versions 9.20.0 through 9.20.24 BIND 9 versions 9.18.11-S1 through 9.18.50-S1 BIND 9 versions 9.20.9-S1 through 9.20.24-S1
Description Unexpected program termination occurs in named due to the ordering or specific content of responses to queries for A records combined with CNAME or DNAME records. This happens in two scenarios: first, when a client queries for a DNAME and an A record below that DNAME, and the authoritative server provides a positive A response but a delayed negative DNAME response. Second, when a client queries for a CNAME and an A record for the same name, and the server provides a positive A response followed by a delayed self-referential CNAME response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93138
CVE-2026-12617
ECHO-6D4B-E3EE-0962
MGASA-2026-0331
OESA-2026-3289
OESA-2026-3290
OESA-2026-3291
OPENSUSE-SU-2026:11375-1
OPENSUSE-SU-2026:21489-1
RHSA-2026:54071
SUSE-SU-2026:3426-1
SUSE-SU-2026:3452-1
USN-8648-1

Affected Products

Bind 9
Ubuntu