CVE-2026-11622
HIGHISC BIND 9 - Potential Memory Usage Beyond Configured Limits
Title source: ruleDescription
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
References (3)
Core 3
Core References
Patch patch
https://downloads.isc.org/isc/bind9/9.20.26
Patch patch
https://downloads.isc.org/isc/bind9/9.21.24
Scores
CVSS v3
7.5
EPSS
0.0051
EPSS Percentile
40.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (5)
ISC/BIND 9
9.11.0 - 9.18.50
ISC/BIND 9
9.11.3-S1 - 9.18.50-S1
ISC/BIND 9
9.20.0 - 9.20.24
ISC/BIND 9
9.20.9-S1 - 9.20.24-S1
ISC/BIND 9
9.21.0 - 9.21.23
Published
Jul 22, 2026
Tracked Since
Jul 22, 2026