Wiz rejoint Google Cloud : Faire de la magie ensemble

CVE-2026-75029
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-75029 is a Denial of Service vulnerability in ISC BIND 9 caused by improper handling of duplicate records in DNS query responses. An attacker can send named multiple copies of a record that should only exist once (e.g., an SOA record), causing the RDATA to be repeatedly appended to the in-memory RDATA set, leading to increased memory usage in the negative cache and potentially other memory-based attack vectors. The vulnerability affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and corresponding BIND Supported Preview Edition versions (9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1). It was disclosed on September 16, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Github Advisory).

Détails techniques

The root cause is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-405 (Asymmetric Resource Consumption / Amplification). When named processes a query response, it fails to deduplicate records that should be unique (such as SOA records); if the RDATA is identical across duplicate copies, each copy is appended to the in-memory RDATA set rather than being discarded. This allows a network-adjacent or remote attacker — without any authentication or user interaction — to craft DNS responses containing many duplicate records, causing unbounded growth of the negative cache's memory footprint and potentially enabling further memory-based exploitation (Red Hat Bugzilla, Github Advisory).

Impact

Successful exploitation results in increased memory consumption of the BIND named process, which can degrade DNS service availability and potentially lead to a full denial of service if memory is exhausted. There is no impact on confidentiality or integrity; the availability impact is rated Low under CVSS, though sustained or amplified attacks could escalate the practical severity. Organizations relying on BIND for critical DNS infrastructure may experience service disruptions affecting name resolution for dependent systems (Red Hat Advisory, Github Advisory).

Exploitabilité

As of the disclosure date (September 16, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication and no user interaction, making it accessible to any network attacker, but exploitation complexity is low only in the sense that crafting duplicate-record DNS responses is straightforward for a capable adversary (Red Hat Advisory, Github Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify target DNS resolvers running a vulnerable version of BIND 9 (9.11.0–9.18.50, 9.20.0–9.20.27, or 9.21.0–9.21.25) using DNS banner queries or version-disclosing responses.
  2. Set up a malicious authoritative DNS server: Configure a rogue authoritative name server that returns crafted DNS responses containing many duplicate copies of a singleton record (e.g., multiple identical SOA records) for a domain the attacker controls.
  3. Trigger resolver queries: Cause the target BIND resolver to query the attacker-controlled authoritative server — for example, by sending DNS queries for names under the attacker's domain to the resolver, or by poisoning referrals.
  4. Deliver duplicate-record responses: The rogue server responds with DNS messages containing many copies of the same SOA (or similar) record with identical RDATA, causing named to append each copy to the in-memory RDATA set.
  5. Exhaust memory: Repeat the process at scale or with high frequency to continuously grow the negative cache memory usage, potentially causing named to exhaust available memory and crash or become unresponsive (Red Hat Bugzilla, Github Advisory).

Indicateurs de compromis

  • Process: Abnormal and continuously growing memory consumption by the named process (monitor via top, ps, or system monitoring tools).
  • Logs: Unusual volume of DNS queries to a specific external domain or authoritative server in BIND query logs (/var/log/named/ or syslog), particularly repeated lookups for the same name.
  • Network: High rate of DNS response traffic from an unexpected or unknown authoritative server containing anomalously large or malformed response payloads; DNS responses with an unusually high answer count for singleton record types (e.g., multiple SOA records in a single response).
  • System: Out-of-memory (OOM) killer events in system logs (/var/log/messages, dmesg) targeting the named process; unexpected named crashes or restarts.

Atténuation et solutions de contournement

ISC has released patched versions BIND 9.20.29 and 9.21.26 that address this vulnerability; users should upgrade to these versions as the primary remediation (Github Advisory). As interim mitigations, administrators should implement rate limiting on DNS query responses (e.g., using BIND's rate-limit configuration option) and apply response policy zones (RPZ) or firewall rules to filter anomalous DNS traffic. Monitoring BIND process memory consumption for abnormal growth can serve as an early warning of exploitation attempts (Red Hat Advisory).

Réactions de la communauté

The vulnerability was reported across multiple security tracking platforms including Red Hat Bugzilla, the ENISA European Vulnerability Database (EUVD-2026-80786), and the oss-security mailing list shortly after disclosure. Coverage noted it as one of 14 BIND 9 vulnerabilities patched in the 9.20.29 and 9.21.26 releases (Linux Compatible). No significant independent researcher commentary or social media discussion has been identified at this time.

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Fixe

bookworm

bind9

Affecté

sid

bind9: 1:9.20.29-1

Fixe

trixie

bind9

Affecté

RHEL / CentOS

Affecté

OpenShift

openshift/ose-rhel-coreos-8

Affecté

SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-80274HIGH7.5
  • Linux Debian logoLinux Debian
  • bind9
NonNonSep 16, 2026
CVE-2026-76163HIGH7.5
  • Linux Debian logoLinux Debian
  • bind9
NonNonSep 16, 2026
CVE-2026-42784HIGH7.4
  • Linux Debian logoLinux Debian
  • rust-sequoia-openpgp+crypto-nettle-devel
NonOuiSep 16, 2026
CVE-2026-77119MEDIUM5.9
  • Linux Debian logoLinux Debian
  • bind9.16-utils
NonNonSep 16, 2026
CVE-2026-75029MEDIUM5.3
  • Linux Debian logoLinux Debian
  • bind9
NonNonSep 16, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités