
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19666 is a Denial of Service vulnerability in ISC BIND 9 affecting resolvers configured to use the dns64 feature. When an authoritative server returns a malformed DNS answer of a specific type, the named resolver process exits unexpectedly, disrupting DNS resolution for all dependent clients. The vulnerability was published on September 16, 2026, and affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and the corresponding BIND Supported Preview Edition (S1) branches. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, GitHub Advisory).
The vulnerability is classified under CWE-617 (Reachable Assertion) and CWE-416 (Use After Free), indicating that the malformed DNS response triggers either an assertion failure or a use-after-free condition within the dns64 processing code path of named. The attack vector is network-based, requiring no authentication or user interaction, and exploits the way BIND's dns64 module handles specific malformed answers from authoritative servers. The precondition for exploitation is that the targeted resolver must have dns64 explicitly configured in its named.conf; resolvers not using dns64 are unaffected (Red Hat Bugzilla, GitHub Advisory).
Successful exploitation causes the named process to crash unexpectedly, resulting in a complete loss of DNS resolution availability for all clients relying on the affected resolver. The impact is limited to availability — there is no confidentiality or integrity impact, and no evidence of code execution or data exfiltration potential. In environments where the affected resolver is a critical infrastructure component, repeated exploitation could constitute a sustained denial-of-service condition (Red Hat Advisory, GitHub Advisory).
As of the disclosure date (September 16, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory, GitHub Advisory).
dns64 enabled. This can be done via DNS version queries (dig CHAOS TXT version.bind @<target>) or banner-grabbing tools.dns64 configured by sending AAAA queries for IPv4-only domains and observing synthesized IPv6 responses, which indicate dns64 is active.dns64 code path.named to exit unexpectedly.named from recovering if automatic restart mechanisms are in place (Red Hat Bugzilla, GitHub Advisory).named process termination entries in /var/log/named/ or system logs (e.g., syslog, journald) with assertion failure or segmentation fault messages; BIND log entries referencing dns64 processing errors.named process; automatic restart events logged by systemd or init for the named service.ISC has released patched versions BIND 9.20.29 and 9.21.26 which address this vulnerability; administrators should upgrade to these versions as the primary remediation (GitHub Advisory). As a temporary workaround, disabling the dns64 feature in named.conf (if not operationally required) eliminates the attack surface entirely. Additionally, implementing network-level controls to filter or validate DNS responses from untrusted authoritative sources can reduce exposure until patching is feasible (Red Hat Advisory).
The vulnerability was reported across multiple security tracking platforms including VulnDB, OSS-Security mailing list, and Linux compatibility news outlets shortly after disclosure on September 16, 2026. Coverage noted that ISC patched 14 BIND 9 vulnerabilities simultaneously in the 9.20.29 and 9.21.26 releases (Linux Compatible). No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking activity.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
bind9
devel
bind9
focal (esm-infra)
bind9
jammy
bind9
noble
bind9
noble (esm-apps)
isc-dhcp
resolute
bind9
resolute (esm-apps)
isc-dhcp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."