Back

MEDIUM

Amplification vulnerabilities via self-pointed glue records

Published May 20, 2026

Description

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.49, 9.20.23, 9.21.22, 9.18.49-S1, or 9.20.23-S1.

Red Hat statement

Moderate: This vulnerability in BIND resolvers allows for an amplified resource consumption attack. A specially crafted DNS zone can cause a Red Hat system acting as a resolver to consume excessive resources, potentially leading to a denial of service.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published May 20, 2026
Updated May 20, 2026
Reserved Mar 5, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity Moderate
Public date May 26, 2026