Back to overview

CVE-2026-11622

HIGH
7.5
CVSS 3.1
Description
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Metadata

CVE ID
CVE-2026-11622
State
PUBLISHED
Assigner
isc
Reserved
2026-06-08 20:17 UTC
Published
2026-07-22 14:12 UTC
Last updated
2026-07-22 14:12 UTC
Primary CWE
CWE-770
CWE-770 Allocation of Resources Without Limits or Throttling
Vendor / Product
ISC / BIND 9
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products (1)
VendorProductPlatformVersions
ISC BIND 9 9.11.0 ≤ 9.18.50, 9.20.0 ≤ 9.20.24, 9.21.0 ≤ 9.21.23, 9.11.3-S1 ≤ 9.18.50-S1 …
Weakness (CWE)
CWESourceDescription
CWE-770 cna CWE-770 Allocation of Resources Without Limits or Throttling
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview