CVE-2026-1519
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-1519 is a denial-of-service vulnerability in ISC BIND 9 where a BIND resolver performing DNSSEC validation may consume excessive CPU when it encounters a maliciously crafted DNS zone. The vulnerability was published on March 25, 2026, and affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and corresponding Supported Preview Edition (S) branches. Authoritative-only servers are generally unaffected unless they perform recursive queries. It carries a CVSS v3.1 base score of 7.5 (High) (ISC Advisory, Red Hat CVE).

Technical details

The root cause is classified under CWE-606 (Unchecked Input for Loop Condition) and CWE-770 (Allocation of Resources Without Limits or Throttling). When a BIND resolver with DNSSEC validation enabled processes a specially crafted zone — specifically one involving excessive NSEC3 iterations during insecure delegation validation — it enters a computationally expensive loop without adequate bounds checking, leading to CPU exhaustion. The attack requires no authentication, no user interaction, and is exploitable remotely over the network. No preconditions beyond the resolver having DNSSEC validation enabled are required (ISC Advisory, Infinit Sec).

Impact

Successful exploitation causes the BIND resolver to consume excessive CPU resources, degrading or completely disabling DNS resolution services for all clients relying on the affected resolver. The impact is limited to availability — there is no confidentiality or integrity impact. Organizations relying on BIND for recursive DNS resolution could experience widespread DNS outages, potentially affecting all downstream services and users dependent on that resolver (ISC Advisory, Red Hat CVE).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (ISC Advisory). The EPSS score is approximately 0.036%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection plugins are available from Nessus (e.g., plugin IDs 303599, 303734, 303759) and Qualys (e.g., detection ID 288362).

Exploitation steps

  1. Reconnaissance: Identify internet-facing BIND resolvers with DNSSEC validation enabled using tools such as Shodan or Censys, targeting versions within the affected ranges (e.g., 9.18.0–9.18.46, 9.20.0–9.20.20).
  2. Craft malicious DNS zone: Prepare a specially crafted DNS zone containing records designed to trigger excessive NSEC3 iteration processing during insecure delegation validation, exploiting the unchecked loop condition.
  3. Serve the malicious zone: Host the crafted zone on an attacker-controlled authoritative DNS server that is reachable by the target resolver.
  4. Trigger validation: Cause the target BIND resolver to query the malicious zone — for example, by inducing a client to resolve a domain name delegated to the attacker's authoritative server.
  5. Achieve denial of service: The resolver's DNSSEC validation process enters a CPU-intensive loop processing the malicious zone data, consuming excessive CPU and degrading or halting DNS resolution services (ISC Advisory, Infinit Sec).

Indicators of compromise

  • Process: Sustained high CPU utilization (near 100%) by the named process on BIND resolver hosts without a corresponding spike in legitimate query volume.
  • Logs: BIND query logs (/var/log/named/ or syslog) showing repeated resolution attempts for unusual or unfamiliar domain names, particularly those with DNSSEC-signed delegations from unknown authoritative servers.
  • Network: Unusual outbound DNS queries from the resolver to previously unseen authoritative name servers; elevated query rates to a specific delegated zone.
  • System: System load averages significantly elevated on the DNS resolver host; potential timeouts or failures reported by clients relying on the resolver for name resolution.

Mitigation and workarounds

ISC has released patched versions: 9.18.47, 9.20.21, and 9.21.20. Operators should upgrade to the appropriate patched version for their branch as the primary remediation (ISC Advisory, ISC Downloads). As a workaround where upgrading is not immediately possible, administrators may consider disabling DNSSEC validation if it is not operationally required and acceptable within their security posture. Additionally, implementing rate limiting on DNS queries and monitoring for anomalous CPU consumption can help detect and limit the impact of exploitation attempts. Downstream vendors including Red Hat (RHSA-2026:7915, RHSA-2026:8075, RHSA-2026:8155), Ubuntu (USN-8124-1), Debian (DSA-6181-1), SUSE, Fedora, Amazon Linux, and IBM have also released patches (Red Hat Errata, Ubuntu Advisory).

Community reactions

The vulnerability received broad coverage across the Linux and security community, with advisories issued by multiple national cybersecurity agencies including the Canadian Centre for Cyber Security (AV26-280) and Belgium's CCB. Security news outlets including GBHackers, CyberPress, and The Hacker News covered the BIND 9 security update release. The oss-security mailing list also carried a disclosure notice. Community reaction was measured, noting the lack of public PoC and the straightforward remediation path via vendor patches (Canadian CCCS, GBHackers, The Hacker News).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management