Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75029
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2026-75029 is a Denial of Service vulnerability in ISC BIND 9 caused by improper handling of duplicate records in DNS query responses. An attacker can send named multiple copies of a record that should only exist once (e.g., an SOA record), causing the RDATA to be repeatedly appended to the in-memory RDATA set, leading to increased memory usage in the negative cache and potentially other memory-based attack vectors. The vulnerability affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and corresponding BIND Supported Preview Edition versions (9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1). It was disclosed on September 16, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Github Advisory).

Technical details

The root cause is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-405 (Asymmetric Resource Consumption / Amplification). When named processes a query response, it fails to deduplicate records that should be unique (such as SOA records); if the RDATA is identical across duplicate copies, each copy is appended to the in-memory RDATA set rather than being discarded. This allows a network-adjacent or remote attacker — without any authentication or user interaction — to craft DNS responses containing many duplicate records, causing unbounded growth of the negative cache's memory footprint and potentially enabling further memory-based exploitation (Red Hat Bugzilla, Github Advisory).

Impact

Successful exploitation results in increased memory consumption of the BIND named process, which can degrade DNS service availability and potentially lead to a full denial of service if memory is exhausted. There is no impact on confidentiality or integrity; the availability impact is rated Low under CVSS, though sustained or amplified attacks could escalate the practical severity. Organizations relying on BIND for critical DNS infrastructure may experience service disruptions affecting name resolution for dependent systems (Red Hat Advisory, Github Advisory).

Exploitability

As of the disclosure date (September 16, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication and no user interaction, making it accessible to any network attacker, but exploitation complexity is low only in the sense that crafting duplicate-record DNS responses is straightforward for a capable adversary (Red Hat Advisory, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify target DNS resolvers running a vulnerable version of BIND 9 (9.11.0–9.18.50, 9.20.0–9.20.27, or 9.21.0–9.21.25) using DNS banner queries or version-disclosing responses.
  2. Set up a malicious authoritative DNS server: Configure a rogue authoritative name server that returns crafted DNS responses containing many duplicate copies of a singleton record (e.g., multiple identical SOA records) for a domain the attacker controls.
  3. Trigger resolver queries: Cause the target BIND resolver to query the attacker-controlled authoritative server — for example, by sending DNS queries for names under the attacker's domain to the resolver, or by poisoning referrals.
  4. Deliver duplicate-record responses: The rogue server responds with DNS messages containing many copies of the same SOA (or similar) record with identical RDATA, causing named to append each copy to the in-memory RDATA set.
  5. Exhaust memory: Repeat the process at scale or with high frequency to continuously grow the negative cache memory usage, potentially causing named to exhaust available memory and crash or become unresponsive (Red Hat Bugzilla, Github Advisory).

Indicators of compromise

  • Process: Abnormal and continuously growing memory consumption by the named process (monitor via top, ps, or system monitoring tools).
  • Logs: Unusual volume of DNS queries to a specific external domain or authoritative server in BIND query logs (/var/log/named/ or syslog), particularly repeated lookups for the same name.
  • Network: High rate of DNS response traffic from an unexpected or unknown authoritative server containing anomalously large or malformed response payloads; DNS responses with an unusually high answer count for singleton record types (e.g., multiple SOA records in a single response).
  • System: Out-of-memory (OOM) killer events in system logs (/var/log/messages, dmesg) targeting the named process; unexpected named crashes or restarts.

Mitigation and workarounds

ISC has released patched versions BIND 9.20.29 and 9.21.26 that address this vulnerability; users should upgrade to these versions as the primary remediation (Github Advisory). As interim mitigations, administrators should implement rate limiting on DNS query responses (e.g., using BIND's rate-limit configuration option) and apply response policy zones (RPZ) or firewall rules to filter anomalous DNS traffic. Monitoring BIND process memory consumption for abnormal growth can serve as an early warning of exploitation attempts (Red Hat Advisory).

Community reactions

The vulnerability was reported across multiple security tracking platforms including Red Hat Bugzilla, the ENISA European Vulnerability Database (EUVD-2026-80786), and the oss-security mailing list shortly after disclosure. Coverage noted it as one of 14 BIND 9 vulnerabilities patched in the 9.20.29 and 9.21.26 releases (Linux Compatible). No significant independent researcher commentary or social media discussion has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

bind9

Affected

sid

bind9: 1:9.20.29-1

Fixed

trixie

bind9: 1:9.20.29-1~deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-infra)

bind9

Unknown

devel

bind9

Unknown

focal (esm-infra)

bind9

Unknown

jammy

bind9

Unknown

noble

bind9

Unknown

noble (esm-apps)

isc-dhcp

Unknown

resolute

bind9

Unknown

resolute (esm-apps)

isc-dhcp

Unknown

RHEL / CentOS

Affected

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

bind.src

Affected

RHEL 9

bind.src

Affected

RHEL 10

bind.src

Affected

SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80274HIGH7.5
  • Alma Linux logoAlma Linux
  • bind9.16-doc
NoYesSep 16, 2026
CVE-2026-19666HIGH7.5
  • Alma Linux logoAlma Linux
  • bind9.16.src
NoYesSep 16, 2026
CVE-2026-19033MEDIUM6.5
  • Alma Linux logoAlma Linux
  • bind-utils
NoYesSep 16, 2026
CVE-2026-77119MEDIUM5.9
  • Alma Linux logoAlma Linux
  • bind-pkcs11-utils
NoYesSep 16, 2026
CVE-2026-75029MEDIUM5.3
  • Alma Linux logoAlma Linux
  • bind.src
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management