Back

MEDIUM

Unbounded resend loop in BIND 9 resolver

Published May 20, 2026

Description

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.49, 9.20.23, 9.21.22, 9.18.49-S1, or 9.20.23-S1.

Red Hat statement

Moderate: This flaw in the BIND 9 resolver's state machine can lead to severe resource exhaustion. A remote, unauthenticated attacker could exploit this by sending specially crafted queries that trigger an unbounded resend loop during bad-server handling, potentially causing a denial of service in affected Red Hat products utilizing BIND as a resolver.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published May 20, 2026
Updated May 20, 2026
Reserved Apr 9, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Moderate
Public date May 26, 2026