
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75029 is a Denial of Service vulnerability in ISC BIND 9 caused by improper handling of duplicate records in DNS query responses. An attacker can send named multiple copies of a record that should only exist once (e.g., an SOA record), causing the RDATA to be repeatedly appended to the in-memory RDATA set, leading to increased memory usage in the negative cache and potentially other memory-based attack vectors. The vulnerability affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and corresponding BIND Supported Preview Edition versions (9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1). It was disclosed on September 16, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Github Advisory).
The root cause is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-405 (Asymmetric Resource Consumption / Amplification). When named processes a query response, it fails to deduplicate records that should be unique (such as SOA records); if the RDATA is identical across duplicate copies, each copy is appended to the in-memory RDATA set rather than being discarded. This allows a network-adjacent or remote attacker — without any authentication or user interaction — to craft DNS responses containing many duplicate records, causing unbounded growth of the negative cache's memory footprint and potentially enabling further memory-based exploitation (Red Hat Bugzilla, Github Advisory).
Successful exploitation results in increased memory consumption of the BIND named process, which can degrade DNS service availability and potentially lead to a full denial of service if memory is exhausted. There is no impact on confidentiality or integrity; the availability impact is rated Low under CVSS, though sustained or amplified attacks could escalate the practical severity. Organizations relying on BIND for critical DNS infrastructure may experience service disruptions affecting name resolution for dependent systems (Red Hat Advisory, Github Advisory).
As of the disclosure date (September 16, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication and no user interaction, making it accessible to any network attacker, but exploitation complexity is low only in the sense that crafting duplicate-record DNS responses is straightforward for a capable adversary (Red Hat Advisory, Github Advisory).
named to append each copy to the in-memory RDATA set.named to exhaust available memory and crash or become unresponsive (Red Hat Bugzilla, Github Advisory).named process (monitor via top, ps, or system monitoring tools)./var/log/named/ or syslog), particularly repeated lookups for the same name./var/log/messages, dmesg) targeting the named process; unexpected named crashes or restarts.ISC has released patched versions BIND 9.20.29 and 9.21.26 that address this vulnerability; users should upgrade to these versions as the primary remediation (Github Advisory). As interim mitigations, administrators should implement rate limiting on DNS query responses (e.g., using BIND's rate-limit configuration option) and apply response policy zones (RPZ) or firewall rules to filter anomalous DNS traffic. Monitoring BIND process memory consumption for abnormal growth can serve as an early warning of exploitation attempts (Red Hat Advisory).
The vulnerability was reported across multiple security tracking platforms including Red Hat Bugzilla, the ENISA European Vulnerability Database (EUVD-2026-80786), and the oss-security mailing list shortly after disclosure. Coverage noted it as one of 14 BIND 9 vulnerabilities patched in the 9.20.29 and 9.21.26 releases (Linux Compatible). No significant independent researcher commentary or social media discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
bind9
devel
bind9
focal (esm-infra)
bind9
jammy
bind9
noble
bind9
noble (esm-apps)
isc-dhcp
resolute
bind9
resolute (esm-apps)
isc-dhcp
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."