Potential wildcard CNAME RPZ policy bypass
Published Jul 22, 2026
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Affected products
-
- Version 9.16.0StatusaffectedConstraints<=9.18.50
- Version 9.16.8-S1StatusaffectedConstraints<=9.18.50-S1
- Version 9.20.0StatusaffectedConstraints<=9.20.24
- Version 9.20.9-S1StatusaffectedConstraints<=9.20.24-S1
- Version 9.21.0StatusaffectedConstraints<=9.21.23
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
bind-32:9.18.33-15.el10_2.10
Fixed · RHSA-2026:55437
Red Hat Enterprise Linux 8
bind9.16-32:9.16.23-0.22.el8_10.12
Fixed · RHSA-2026:54509
Red Hat Enterprise Linux 9
bind-32:9.16.23-40.el9_8.8
Fixed · RHSA-2026:54510
Red Hat Enterprise Linux 9
bind9.18-32:9.18.29-14.el9_8.8
Fixed · RHSA-2026:55442
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
bind-32:9.16.23-18.el9_4.12
Fixed · RHSA-2026:57189
Red Hat Enterprise Linux 9.6 Extended Update Support
bind-32:9.16.23-31.el9_6.4
Fixed · RHSA-2026:55441
Red Hat Hardened Images
bind-main-9.20.26-0.1.hum1
Fixed · RHSA-2026:54071
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202609011112-0
Fixed · RHSA-2026:62549
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202609031320-0
Fixed · RHSA-2026:65851
Red Hat OpenShift Container Platform 4.22
rhcos-4.22.9.8.202608251819-0
Fixed · RHSA-2026:60440
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | bind-32:9.18.33-15.el10_2.10 | Fixed | RHSA-2026:55437 |
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.22.el8_10.12 | Fixed | RHSA-2026:54509 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-40.el9_8.8 | Fixed | RHSA-2026:54510 |
| Red Hat Enterprise Linux 9 | bind9.18-32:9.18.29-14.el9_8.8 | Fixed | RHSA-2026:55442 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | bind-32:9.16.23-18.el9_4.12 | Fixed | RHSA-2026:57189 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | bind-32:9.16.23-31.el9_6.4 | Fixed | RHSA-2026:55441 |
| Red Hat Hardened Images | bind-main-9.20.26-0.1.hum1 | Fixed | RHSA-2026:54071 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202609011112-0 | Fixed | RHSA-2026:62549 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202609031320-0 | Fixed | RHSA-2026:65851 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202608251819-0 | Fixed | RHSA-2026:60440 |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.26, 9.21.24, or 9.20.26-S1.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 22, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.43% (0.00428) | 34.75th | v5 (v2026.06.15) |
| Jul 23, 2026 | 0.54% (0.00543) | 42.27th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-11331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2503721 Issue Tracking
- https://downloads.isc.org/isc/bind9/9.20.26 patch
- https://downloads.isc.org/isc/bind9/9.21.24 patch
- https://kb.isc.org/docs/cve-2026-11331 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-11331
- https://www.cve.org/CVERecord?id=CVE-2026-11331
Change history (0)
No recorded changes yet.