ISC Fixes 14 Critical Vulnerabilities in BIND 9 Security Update

www.news4hackers.com-isc-fixes-14-critical-vulnerabilities-in-bind-9-security-update-isc-fixes-14-critical-vulnerabilities-in-bind-9-security-update

Internet Systems Consortium (ISC) has issued security updates for BIND, an open source domain name system (DNS) server, addressing 14 vulnerabilities that could enable denial-of-service (DoS) attacks.

Security Updates for BIND

The patches resolve seven high-severity flaws capable of triggering unexpected program termination, memory depletion, named process termination, and resource exhaustion. These vulnerabilities are exploitable remotely and are tracked as CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736. Attackers can exploit these issues through mismatched NOQNAME proof, QTYPE TKEY queries, malformed authoritative server responses, SVCB/HTTPS AliasMode records, crafted DNS-over-HTTPS (DoH) requests, and 65,536-byte negative answers.

High-Severity Vulnerabilities

CVE-2026-77692 is particularly critical as it allows remote exploitation without authentication, crashing the named process via a single DoH SIG(0) request with a cryptographically invalid record.

CVE-2026-77692 is particularly critical as it allows remote exploitation without authentication, crashing the named process via a single DoH SIG(0) request with a cryptographically invalid record.

The update also addresses seven medium-severity flaws, including risks of cache poisoning, excessive negative cache memory usage, CPU exhaustion, packet loss, unauthorized zone data injection, and DoS scenarios.

Resolution and Recommendations

Patched Versions

All vulnerabilities were resolved in BIND versions 9.21.26 and 9.20.29.

Security Advisory

ISC has not identified any of these flaws being actively exploited in the wild but urges immediate deployment of the updated versions. Further details are available in BIND’s security advisories and release notes.



About Author

en_USEnglish