A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
Published Mar 25, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.32%
Description
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Affected products
-
- Version 9.20.0StatusaffectedConstraints<=9.20.20
- Version 9.20.9-S1StatusaffectedConstraints<=9.20.20-S1
- Version 9.21.0StatusaffectedConstraints<=9.21.19
- Version 9.18.0StatusunaffectedConstraints<=9.18.46
- Version 9.18.11-S1StatusunaffectedConstraints<=9.18.46-S1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
Red Hat Hardened Images
bind-main-9.18.48-1.hum1
Fixed · RHSA-2026:6935
Red Hat Enterprise Linux 10
bind
Fix deferred
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 8
bind9.16
Not affected
Red Hat Enterprise Linux 9
bind
Not affected
Red Hat Enterprise Linux 9
bind9.18
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | bind-main-9.18.48-1.hum1 | Fixed | RHSA-2026:6935 |
| Red Hat Enterprise Linux 10 | bind | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind9.16 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind9.18 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.21, 9.21.20, or 9.20.21-S1.
Red Hat statement
This vulnerability has a Moderate impact. A use-after-return flaw in the `named` server of `bind9` allows a remote attacker to send a specially-crafted DNS request signed with SIG(0). This can lead to improper Access Control List (ACL) matching, potentially granting unauthorized access to resources. Red Hat Enterprise Linux 8 and 9 ship with BIND versions 9.16 and 9.18 respectively, which are not affected by this flaw. Red Hat Enterprise Linux 10 is affected.
Red Hat mitigation
Restrict network access to the `named` service to trusted clients and networks. Configure firewall rules to limit inbound connections to the DNS service port (UDP/TCP 53). For example, using `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="53" protocol="udp" accept'` and `firewall-cmd --reload`. This action may impact DNS resolution for clients outside the specified trusted networks. A service reload or restart may be required for changes to take effect.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Mar 25, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.32% (0.00324) | 23.15th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.36% (0.00360) | 27.66th | v5 (v2026.06.15) |
| Mar 26, 2026 | 0.01% (0.00011) | 1.30th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-3591 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451298 Issue Tracking
- https://downloads.isc.org/isc/bind9/9.20.21 patch
- https://downloads.isc.org/isc/bind9/9.21.20 patch
- https://kb.isc.org/docs/cve-2026-3591 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3591
- https://www.cve.org/CVERecord?id=CVE-2026-3591
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-3591 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2451298 | Issue Tracking | |
| https://downloads.isc.org/isc/bind9/9.20.21 | patch | |
| https://downloads.isc.org/isc/bind9/9.21.20 | patch | |
| https://kb.isc.org/docs/cve-2026-3591 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-3591 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-3591 |
Change history (0)
No recorded changes yet.