CVE-2026-3104
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-3104 is a memory leak vulnerability in ISC BIND 9 that allows an unauthenticated remote attacker to cause a denial of service by querying a specially crafted domain against an affected resolver. It was disclosed on March 25, 2026, and affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1; BIND 9.18.x branches are explicitly not affected. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (ISC KB, Red Hat, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-772 (Missing Release of Resource after Effective Lifetime) and CWE-401 (Missing Release of Memory after Effective Lifetime), indicating that memory allocated during the processing of certain DNS queries is never freed. Specifically, the flaw resides in the code path that prepares DNSSEC proofs of non-existence (NSEC/NSEC3 records); a specially crafted domain name triggers this code path and causes a persistent memory leak with each query. Because the attack requires only a network-reachable resolver and no authentication or user interaction, exploitation complexity is low. No public proof-of-concept code has been identified at this time (ISC KB, Red Hat Bugzilla).

Impact

Successful exploitation causes progressive memory exhaustion on the affected BIND resolver, ultimately rendering the DNS service unavailable — a denial-of-service condition. There is no confidentiality or integrity impact; the vulnerability is purely an availability threat. Because DNS is foundational infrastructure, an unavailable resolver can cascade into broader service outages affecting all systems that depend on name resolution, including web applications, authentication services, and internal network communications (ISC KB, Red Hat).

Exploitability

No public proof-of-concept exploit or in-the-wild exploitation has been reported as of the time of this report (ISC KB). The EPSS score is approximately 0.028%, reflecting a currently low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it straightforward to weaponize if a functional exploit is developed (Red Hat).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible BIND resolvers running versions 9.20.0–9.20.20, 9.21.0–9.21.19, or 9.20.9-S1–9.20.20-S1 using tools such as Shodan, Censys, or active DNS banner probing.
  2. Craft malicious domain: Register or control a domain configured to trigger the DNSSEC proof-of-non-existence code path in the resolver (e.g., a domain with specific NSEC/NSEC3 zone configuration designed to elicit the vulnerable memory allocation).
  3. Send repeated queries: Repeatedly query the specially crafted domain against the target resolver using standard DNS query tools (e.g., dig, nslookup, or custom scripts), causing the resolver to allocate memory that is never released.
  4. Exhaust memory: Continue querying until the resolver's available memory is depleted, causing the BIND process to become unresponsive or crash, resulting in a denial-of-service condition for all clients relying on that resolver (ISC KB, Red Hat Bugzilla).

Indicators of compromise

  • Network: Sustained high volume of DNS queries from one or more external sources targeting the same unusual or newly registered domain; queries specifically eliciting NSEC/NSEC3 responses.
  • Process/System: Steadily increasing memory consumption by the named process over time without a corresponding increase in legitimate query load; eventual OOM (out-of-memory) kills or BIND process crashes.
  • Logs: BIND query logs (/var/log/named/ or syslog) showing repeated queries for the same crafted domain from the same source IP; potential SERVFAIL responses as memory exhaustion progresses.
  • System Metrics: Alerts from monitoring systems (e.g., Nagios, Prometheus) indicating BIND memory usage trending upward abnormally or DNS service becoming unresponsive.

Mitigation and workarounds

ISC has released fixed versions BIND 9.20.21 and BIND 9.21.20 that resolve this vulnerability; operators should upgrade immediately (ISC KB, ISC Downloads 9.20.21, ISC Downloads 9.21.20). Organizations running BIND 9.18.x (including 9.18.0–9.18.46 and 9.18.11-S1–9.18.46-S1) are not affected and do not require action for this specific CVE. As an interim measure where patching is not immediately feasible, consider implementing network segmentation to restrict DNS resolver exposure to trusted clients only, and monitor resolver memory usage closely for anomalies. Linux distribution patches are also available for Ubuntu (USN-8124-1), Debian, Fedora, and openSUSE (Ubuntu Advisory).

Community reactions

The Canadian Centre for Cyber Security (CCCS) issued an advisory (AV26-280) urging organizations to patch affected BIND installations promptly (CCCS Advisory). The Belgium Centre for Cybersecurity also published a warning recommending immediate patching of ISC BIND 9 DNS vulnerabilities. Security media including The Hacker News referenced the vulnerability in a weekly recap, and community discussion appeared on Bluesky and Mastodon. Multiple Linux distribution security teams (Ubuntu, Debian, Fedora, openSUSE, SUSE) rapidly issued updated packages, reflecting the broad deployment of BIND across Linux infrastructure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

bind9

Fixed

sid

bind9: 1:9.20.21-1

Fixed

trixie

bind9: 1:9.20.21-1~deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-infra)

bind9

Not Affected

devel

bind9

Not Affected

focal (esm-infra)

bind9

Not Affected

jammy

bind9

Not Affected

noble

bind9

Not Affected

noble (esm-apps)

isc-dhcp

Unknown

questing

bind9: 1:9.20.11-1ubuntu2.2

Fixed

resolute

bind9

Not Affected

RHEL / CentOS

Affected

OpenShift

Not Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

Alpine

Fixed

edge

bind: 9.20.21-r0

Fixed

v3.22

bind: 9.20.21-r0

Fixed

v3.23

bind: 9.20.21-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management