
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12617 is a Denial of Service vulnerability in ISC BIND 9 caused by a reachable assertion that leads to unexpected termination of the named DNS resolver process. The flaw is triggered by specific ordering and content of DNS responses to CNAME/DNAME and A record queries. Affected versions include BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. It was published on July 22, 2026, with a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Github Advisory).
The root cause is a reachable assertion (CWE-617) within the BIND 9 named resolver process, triggered by race-condition-like timing in DNS response handling. Two distinct scenarios can trigger the crash: (1) a client queries for a DNAME and an A record below the DNAME, the authoritative server responds positively to the A query but delays and then responds negatively to the DNAME query; or (2) a client queries for a CNAME and A record for the same name, the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME. In both cases, the unexpected ordering of responses causes named to hit an internal assertion and terminate. No authentication or user interaction is required, and the attack is conducted entirely over the network (Red Hat Bugzilla, ISC KB).
Successful exploitation causes the BIND 9 named resolver process to crash unexpectedly, resulting in a complete loss of DNS resolution availability for all clients relying on the affected resolver. There is no impact on confidentiality or integrity — the vulnerability is purely a Denial of Service. Organizations running affected BIND versions as recursive resolvers could experience widespread DNS outages, potentially disrupting all network services dependent on name resolution (Github Advisory, Red Hat Advisory).
ISC has released patched versions of BIND 9 addressing this vulnerability; administrators should upgrade to versions outside the affected ranges. The patched release referenced in advisories is BIND 9.20.26 (available at https://downloads.isc.org/isc/bind9/9.20.26). Red Hat and other downstream vendors are tracking patch availability via their respective security advisories. Until patching is possible, consider restricting recursive resolver access to trusted clients only to reduce exposure (ISC KB, Red Hat Bugzilla, Github Advisory).
The vulnerability was disclosed by ISC via their knowledge base and coordinated with Red Hat, which filed a high-severity bug report (Bugzilla #2504370) on July 21, 2026. The OSS-Security mailing list also carried a disclosure notice shortly after publication. No notable independent researcher commentary or significant social media discussion has been identified at this time (Red Hat Bugzilla, OSS-Sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."