CVE-2026-3119
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-3119 is a Denial of Service vulnerability in ISC BIND 9 where the named DNS daemon may crash when processing a correctly signed query containing a TKEY record. The vulnerability was disclosed on March 25, 2026, and affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.x are explicitly not affected. It carries a CVSS v3.1 base score of 6.5 (Medium) (ISC KB, Red Hat).

Technical details

The vulnerability is classified under CWE-617 (Reachable Assertion) and CWE-237 (Improper Handling of Structural Elements). The flaw exists in the code path that processes TKEY records within DNS queries; under certain conditions, this code path triggers an assertion failure, causing named to terminate unexpectedly. Critically, the vulnerable code path is only reachable if the incoming DNS request carries a valid Transaction Signature (TSIG) from a key that is explicitly declared in the named configuration — meaning the attacker must already possess a valid TSIG key (ISC KB, Red Hat Bugzilla).

Impact

Successful exploitation causes the named process to crash, resulting in a complete loss of DNS service availability for the affected server. There is no impact on confidentiality or data integrity — the attack is purely a Denial of Service. In environments where the affected BIND instance serves as a critical DNS resolver or authoritative server, a crash could disrupt name resolution for all dependent systems and services until the daemon is restarted (ISC KB, Red Hat).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.012%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to possess a valid TSIG key configured in the target named instance, significantly limiting the attacker pool to trusted or compromised parties with DNS signing credentials.

Exploitation steps

  1. Obtain a valid TSIG key: The attacker must already possess a TSIG key that is declared in the target named configuration. This could be obtained through credential theft, insider access, or compromise of a trusted DNS peer.
  2. Craft a malicious DNS query: Construct a DNS query that includes a TKEY record in the query section or additional records section.
  3. Sign the query with the TSIG key: Apply a valid TSIG signature to the crafted query using the obtained key, ensuring the signature will pass validation by the target named instance.
  4. Send the query to the target: Transmit the signed TKEY-containing query to the target BIND 9 server (UDP/TCP port 53).
  5. Trigger the crash: Under the vulnerable conditions, named processes the TKEY record, hits a reachable assertion failure, and terminates — causing a DNS service outage (ISC KB, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Sudden termination of the named process with an assertion failure message in /var/log/named/ or system logs (e.g., syslog, journald); log entries referencing TKEY record processing errors or assertion failures in BIND source files.
  • Process: Unexpected crash or restart of the named daemon; monitoring alerts for DNS service unavailability or process exit codes indicating abnormal termination.
  • Network: DNS queries containing TKEY record types (QTYPE 249) arriving with valid TSIG signatures from unexpected or unauthorized source IPs; unusual TKEY query volume from known TSIG key holders.
  • File System: Core dump files generated by named in the working directory (e.g., /var/named/ or /var/cache/bind/) following a crash event.

Mitigation and workarounds

ISC has released patched versions: BIND 9.20.21 (for the 9.20 branch) and BIND 9.21.20 (for the 9.21 branch), which resolve this vulnerability. Upgrading to these versions is the primary recommended remediation (ISC KB, ISC Downloads 9.20.21, ISC Downloads 9.21.20). As a defense-in-depth measure, administrators should restrict TSIG key access to only trusted DNS servers that genuinely require zone transfer or query signing, minimizing the number of entities capable of reaching the vulnerable code path. Ubuntu (USN-8124-1), Debian, openSUSE, and Fedora have also released updated packages (Ubuntu Advisory).

Community reactions

The Canadian Centre for Cyber Security (CCCS) issued a security advisory (AV26-280) covering this vulnerability (CCCS Advisory). Security media outlets including GBHackers and CyberPress covered the vulnerability as part of broader BIND 9 security flaw reporting, noting that the flaws could allow attackers to crash DNS servers (GBHackers, CyberPress). The Hacker News included it in a weekly security recap, and the vulnerability was tracked by multiple threat intelligence platforms including Tenable and Qualys shortly after disclosure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

bind9

Fixed

sid

bind9: 1:9.20.21-1

Fixed

trixie

bind9: 1:9.20.21-1~deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-infra)

bind9

Not Affected

devel

bind9

Not Affected

focal (esm-infra)

bind9

Not Affected

jammy

bind9

Not Affected

noble

bind9

Not Affected

noble (esm-apps)

isc-dhcp

Unknown

questing

bind9: 1:9.20.11-1ubuntu2.2

Fixed

resolute

bind9

Not Affected

RHEL / CentOS

Affected

OpenShift

Not Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

bind.src

Affected

Alpine

Fixed

edge

bind: 9.20.21-r0

Fixed

v3.22

bind: 9.20.21-r0

Fixed

v3.23

bind: 9.20.21-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management