PT-2026-63419 · Isc+1 · Bind 9+1

CVE-2026-13204

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.0 through 9.18.50 BIND 9 versions 9.20.0 through 9.20.24 BIND 9 versions 9.21.0 through 9.21.23 BIND 9 versions 9.11.3-S1 through 9.18.50-S1 BIND 9 versions 9.20.9-S1 through 9.20.24-S1
Description BIND may exit unexpectedly with an assertion during the validation of a proof for a provably insecure domain. This occurs when the domain is covered by both an NSEC (Next Secure) and NSEC3 (Next Secure version 3) record at the parent, but an RRSIG (Resource Record Signature) exists for only one of these record types.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54509
ALSA-2026:54510
ALSA-2026:54654
ALSA-2026:55437
ALSA-2026:55442
AZL-93117
CVE-2026-13204
ECHO-FCC4-5D8A-B7AF
MGASA-2026-0331
OESA-2026-3289
OESA-2026-3290
OESA-2026-3291
OESA-2026-3330
OESA-2026-3331
OPENSUSE-SU-2026:11375-1
OPENSUSE-SU-2026:21489-1
RHSA-2026:54071
SUSE-SU-2026:3426-1
SUSE-SU-2026:3452-1
SUSE-SU-2026:3476-1
SUSE-SU-2026:3477-1
SUSE-SU-2026:3484-1
SUSE-SU-2026:3517-1
SUSE-SU-2026:3554-1
USN-8696-1

Affected Products

Bind 9
Rocky Linux