Search CVE reports


Toggle filters

41 – 50 of 43490 results

Status is adjusted based on your filters.


CVE-2026-12617

Medium priority
Needs evaluation

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-11721

Medium priority
Needs evaluation

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-11622

Medium priority
Needs evaluation

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation....

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-11605

Medium priority
Not affected

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Not affected
isc-dhcp Not affected
bind9-libs Not affected
Show less packages

CVE-2026-11331

Medium priority
Needs evaluation

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-10822

Medium priority
Needs evaluation

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-10723

Medium priority
Needs evaluation

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 20.04 LTS
bind9 Needs evaluation
isc-dhcp Not affected
bind9-libs Needs evaluation
Show less packages

CVE-2026-56444

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-56416

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart +...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-55991

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages