CVE-2026-3119

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

History

21 May 2026, 15:24

Type Values Removed Values Added
References () https://downloads.isc.org/isc/bind9/9.20.21 - () https://downloads.isc.org/isc/bind9/9.20.21 - Patch
References () https://downloads.isc.org/isc/bind9/9.21.20 - () https://downloads.isc.org/isc/bind9/9.21.20 - Patch
References () https://kb.isc.org/docs/cve-2026-3119 - () https://kb.isc.org/docs/cve-2026-3119 - Vendor Advisory
CPE cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
Summary
  • (es) Bajo ciertas condiciones, 'named' puede colapsar al procesar una consulta correctamente firmada que contiene un registro TKEY. El código afectado solo se puede acceder si una solicitud entrante tiene una firma de transacción (TSIG) válida de una clave declarada en la configuración de 'named'. Este problema afecta a las versiones de BIND 9 9.20.0 a 9.20.20, 9.21.0 a 9.21.19, y 9.20.9-S1 a 9.20.20-S1. Las versiones de BIND 9 9.18.0 a 9.18.46 y 9.18.11-S1 a 9.18.46-S1 NO están afectadas.
First Time Isc bind
Isc

25 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 14:16

Updated : 2026-05-21 15:24


NVD link : CVE-2026-3119

Mitre link : CVE-2026-3119

CVE.ORG link : CVE-2026-3119


JSON object : View

Products Affected

isc

  • bind
CWE
CWE-617

Reachable Assertion