Sceawere
Vulnerability Detail
CVE-2026-11331Updated Verified Sceawere Triage Sources: NVD / CISA KEV
BIND 9 RPZ Wildcard CNAME Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 6h ago
- Vendor
- ISC
- Product
- BIND 9
- Attack Type
- CWE-790 Improper Filtering of Special Elements
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-07-22T15:16:51.457Z",
"pubdate": "2026-07-22T15:16:51.457Z",
"executiveSummary": "This vulnerability involves improper error handling within the BIND 9 Response Policy Zone (RPZ) processing engine when evaluating wildcard CNAME policies.\nAn unauthenticated remote attacker capable of sending recursive DNS queries to a vulnerable resolver can cause an unexpected software exit, resulting in a Denial of Service (DoS), or potentially bypass configured RPZ rules.\nThe flaw affects multiple branches of the BIND 9 software, specifically versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, as well as associated Supported Preview editions.\nExploitation requires the resolver to utilize RPZ configurations featuring wildcard CNAME policies and relies on the attacker crafting specially designed, overly long query names.\nThe risk implication is severe as it directly threatens the availability of core DNS resolution infrastructure through daemon termination.",
"technicalDetails": "The root cause of the vulnerability resides in the internal error handling logic of BIND 9 when processing Response Policy Zones (RPZ).\nSpecifically, when a resolver processes an RPZ rule that involves wildcard CNAME policies, an attacker can supply or construct an excessively long query name.\nThis oversized query name triggers a NAMETOOLONG error condition during the internal evaluation phase of RPZ processing.\nThe vulnerable component fails to handle this specific error condition correctly and safely.\nStep-by-step, the attack flow proceeds as follows: First, the attacker identifies or infers that the target BIND 9 resolver utilizes RPZ with wildcard CNAME policies. Second, the attacker crafts a query containing a deeply nested or excessively long domain name designed to exceed internal limits. Third, the resolver receives the recursive query and initiates RPZ evaluation against the policy zones. Fourth, during this evaluation, the oversized query name provokes a NAMETOOLONG error. Fifth, due to the absence of proper error management for this condition, the execution flow fails safely, leading directly to an unexpected exit (crash) of the BIND 9 daemon, or otherwise causing the evaluation logic to fail in a manner that defeats the intended RPZ rule.\nThe vulnerability affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.\nExploitation can be performed remotely over the network without authentication or specific privileges, provided the resolver accepts recursive queries and applies the vulnerable RPZ policy configurations."
}