
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3119 is a Denial of Service vulnerability in ISC BIND 9 where the named DNS daemon may crash when processing a correctly signed query containing a TKEY record. The vulnerability was disclosed on March 25, 2026, and affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.x are explicitly not affected. It carries a CVSS v3.1 base score of 6.5 (Medium) (ISC KB, Red Hat).
The vulnerability is classified under CWE-617 (Reachable Assertion) and CWE-237 (Improper Handling of Structural Elements). The flaw exists in the code path that processes TKEY records within DNS queries; under certain conditions, this code path triggers an assertion failure, causing named to terminate unexpectedly. Critically, the vulnerable code path is only reachable if the incoming DNS request carries a valid Transaction Signature (TSIG) from a key that is explicitly declared in the named configuration — meaning the attacker must already possess a valid TSIG key (ISC KB, Red Hat Bugzilla).
Successful exploitation causes the named process to crash, resulting in a complete loss of DNS service availability for the affected server. There is no impact on confidentiality or data integrity — the attack is purely a Denial of Service. In environments where the affected BIND instance serves as a critical DNS resolver or authoritative server, a crash could disrupt name resolution for all dependent systems and services until the daemon is restarted (ISC KB, Red Hat).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.012%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to possess a valid TSIG key configured in the target named instance, significantly limiting the attacker pool to trusted or compromised parties with DNS signing credentials.
named configuration. This could be obtained through credential theft, insider access, or compromise of a trusted DNS peer.named instance.named processes the TKEY record, hits a reachable assertion failure, and terminates — causing a DNS service outage (ISC KB, Red Hat Bugzilla).named process with an assertion failure message in /var/log/named/ or system logs (e.g., syslog, journald); log entries referencing TKEY record processing errors or assertion failures in BIND source files.named daemon; monitoring alerts for DNS service unavailability or process exit codes indicating abnormal termination.named in the working directory (e.g., /var/named/ or /var/cache/bind/) following a crash event.ISC has released patched versions: BIND 9.20.21 (for the 9.20 branch) and BIND 9.21.20 (for the 9.21 branch), which resolve this vulnerability. Upgrading to these versions is the primary recommended remediation (ISC KB, ISC Downloads 9.20.21, ISC Downloads 9.21.20). As a defense-in-depth measure, administrators should restrict TSIG key access to only trusted DNS servers that genuinely require zone transfer or query signing, minimizing the number of entities capable of reaching the vulnerable code path. Ubuntu (USN-8124-1), Debian, openSUSE, and Fedora have also released updated packages (Ubuntu Advisory).
The Canadian Centre for Cyber Security (CCCS) issued a security advisory (AV26-280) covering this vulnerability (CCCS Advisory). Security media outlets including GBHackers and CyberPress covered the vulnerability as part of broader BIND 9 security flaw reporting, noting that the flaws could allow attackers to crash DNS servers (GBHackers, CyberPress). The Hacker News included it in a weekly security recap, and the vulnerability was tracked by multiple threat intelligence platforms including Tenable and Qualys shortly after disclosure.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
bind9
devel
bind9
focal (esm-infra)
bind9
jammy
bind9
noble
bind9
noble (esm-apps)
isc-dhcp
questing
bind9: 1:9.20.11-1ubuntu2.2
resolute
bind9
OpenShift
RHEL 8
RHEL 9
RHEL 10
bind.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."