CVE-2026-11622

HIGH

ISC BIND 9 - Potential Memory Usage Beyond Configured Limits

Title source: rule
STIX 2.1

Description

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
CVE-2026-11622
https://kb.isc.org/docs/cve-2026-11622

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (5)
ISC/BIND 9 9.11.0 - 9.18.50
ISC/BIND 9 9.11.3-S1 - 9.18.50-S1
ISC/BIND 9 9.20.0 - 9.20.24
ISC/BIND 9 9.20.9-S1 - 9.20.24-S1
ISC/BIND 9 9.21.0 - 9.21.23
Published Jul 22, 2026
Tracked Since Jul 22, 2026