Back

HIGH

Potential wildcard CNAME RPZ policy bypass

Published Jul 22, 2026

Description

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.26, 9.21.24, or 9.20.26-S1.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jul 22, 2026
Updated Jul 22, 2026
Reserved Jun 5, 2026
CISA Vulnrichment
Updated Jul 22, 2026
NVD
Status Undergoing Analysis
Modified Jul 22, 2026
Red Hat
Severity Important
Public date Jul 22, 2026