
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3104 is a memory leak vulnerability in ISC BIND 9 that allows an unauthenticated remote attacker to cause a denial of service by querying a specially crafted domain against an affected resolver. It was disclosed on March 25, 2026, and affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1; BIND 9.18.x branches are explicitly not affected. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (ISC KB, Red Hat, Red Hat Bugzilla).
The root cause is classified under CWE-772 (Missing Release of Resource after Effective Lifetime) and CWE-401 (Missing Release of Memory after Effective Lifetime), indicating that memory allocated during the processing of certain DNS queries is never freed. Specifically, the flaw resides in the code path that prepares DNSSEC proofs of non-existence (NSEC/NSEC3 records); a specially crafted domain name triggers this code path and causes a persistent memory leak with each query. Because the attack requires only a network-reachable resolver and no authentication or user interaction, exploitation complexity is low. No public proof-of-concept code has been identified at this time (ISC KB, Red Hat Bugzilla).
Successful exploitation causes progressive memory exhaustion on the affected BIND resolver, ultimately rendering the DNS service unavailable — a denial-of-service condition. There is no confidentiality or integrity impact; the vulnerability is purely an availability threat. Because DNS is foundational infrastructure, an unavailable resolver can cascade into broader service outages affecting all systems that depend on name resolution, including web applications, authentication services, and internal network communications (ISC KB, Red Hat).
No public proof-of-concept exploit or in-the-wild exploitation has been reported as of the time of this report (ISC KB). The EPSS score is approximately 0.028%, reflecting a currently low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it straightforward to weaponize if a functional exploit is developed (Red Hat).
dig, nslookup, or custom scripts), causing the resolver to allocate memory that is never released.named process over time without a corresponding increase in legitimate query load; eventual OOM (out-of-memory) kills or BIND process crashes./var/log/named/ or syslog) showing repeated queries for the same crafted domain from the same source IP; potential SERVFAIL responses as memory exhaustion progresses.ISC has released fixed versions BIND 9.20.21 and BIND 9.21.20 that resolve this vulnerability; operators should upgrade immediately (ISC KB, ISC Downloads 9.20.21, ISC Downloads 9.21.20). Organizations running BIND 9.18.x (including 9.18.0–9.18.46 and 9.18.11-S1–9.18.46-S1) are not affected and do not require action for this specific CVE. As an interim measure where patching is not immediately feasible, consider implementing network segmentation to restrict DNS resolver exposure to trusted clients only, and monitor resolver memory usage closely for anomalies. Linux distribution patches are also available for Ubuntu (USN-8124-1), Debian, Fedora, and openSUSE (Ubuntu Advisory).
The Canadian Centre for Cyber Security (CCCS) issued an advisory (AV26-280) urging organizations to patch affected BIND installations promptly (CCCS Advisory). The Belgium Centre for Cybersecurity also published a warning recommending immediate patching of ISC BIND 9 DNS vulnerabilities. Security media including The Hacker News referenced the vulnerability in a weekly recap, and community discussion appeared on Bluesky and Mastodon. Multiple Linux distribution security teams (Ubuntu, Debian, Fedora, openSUSE, SUSE) rapidly issued updated packages, reflecting the broad deployment of BIND across Linux infrastructure.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
bind9
devel
bind9
focal (esm-infra)
bind9
jammy
bind9
noble
bind9
noble (esm-apps)
isc-dhcp
questing
bind9: 1:9.20.11-1ubuntu2.2
resolute
bind9
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."