Sceawere

Vulnerability Detail

CVE-2026-11605Updated Verified Sceawere Triage Sources: NVD / CISA KEV

BIND DNSSEC Validation Resource Exhaustion

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
6h ago
Vendor
ISC
Product
BIND 9
Attack Type
CWE-408 Incorrect Behavior Order - Early Amplification
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-07-22T15:16:51.573Z",
  "pubdate": "2026-07-22T15:16:51.573Z",
  "executiveSummary": "This vulnerability is a resource exhaustion issue related to DNSSEC validation within the BIND software. The flaw allows an attacker to cause excessive CPU consumption on vulnerable systems by exploiting the DNSSEC validation mechanism.\nThe primary impact of this vulnerability is denial of service (DoS) through CPU resource exhaustion, which can degrade or completely halt name resolution services on affected authoritative servers and validating resolvers.\nThe affected products include BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1. The risk implication is significant degradation of service availability across networks relying on these BIND versions for DNS resolution.\nAn attacker capable of controlling or influencing an authoritative DNS server or zone can exploit this vulnerability without authentication or special privileges. Exploitation requires the attacker to craft or manage a zone that returns numerous valid but superfluous RRSIG records in response to specific queries, compelling the BIND validator to expend disproportionate CPU cycles processing unnecessary cryptographic signatures.",
  "technicalDetails": "The root cause of the vulnerability lies in the algorithmic processing logic of the BIND DNSSEC validator. Specifically, BIND is programmed to validate all Resource Record Signature (RRSIG) records present in a DNS response, regardless of whether those RRSIG records are strictly necessary for the validation of the response data.\nThe vulnerable component is the DNSSEC validation subsystem within BIND 9. The affected versions include BIND 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1. The vulnerability is network-exposed, as BIND processes incoming DNS responses from authoritative servers during standard query resolution.\nExploitation occurs when an attacker sets up or compromises an authoritative DNS server to host a specially crafted zone. When a victim BIND resolver queries this zone, the malicious authoritative server returns a DNS response containing a massive quantity of valid yet superfluous RRSIG records.\nUpon receiving the response, the BIND validator initiates cryptographic verification routines. Because of the architectural behavior, the validator attempts to parse and validate every single RRSIG record included in the payload, rather than filtering out redundant or unneeded signatures. This forces the host system to perform intensive cryptographic computations for every extraneous record.\nThe attack flow proceeds as follows: 1) The attacker configures an authoritative server with a high density of superfluous RRSIG records. 2) A client or the resolver itself initiates a query directed at this zone. 3) The authoritative server responds with the bloated set of RRSIG records. 4) The BIND validator ingests the response and iterates through all RRSIG records to perform cryptographic validation. 5) The resulting CPU resource exhaustion spikes utilization to 100%, causing latency spikes, query timeouts, and a subsequent denial of service for legitimate DNS queries processed by the affected BIND instance.\nNo authentication or elevated privileges are required to trigger this vulnerability, as it manifests during the processing of standard public network traffic responding to DNS queries."
}
CVE-2026-11605: BIND DNSSEC Validation Resource Exhaustion (HIGH Severity, CVSS: 7.5) - Sceawere