CVE-2026-3591

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

History

21 May 2026, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
Summary
  • (es) Una vulnerabilidad de use-after-return existe en el servidor 'named' al manejar consultas DNS firmadas con SIG(0). Usando una solicitud DNS especialmente diseñada, un atacante podría ser capaz de hacer que una ACL haga una coincidencia incorrecta con una dirección IP. En una ACL de permiso predeterminado (negando solo direcciones IP específicas), esto podría llevar a acceso no autorizado. Las ACL de denegación predeterminada deberían fallar de forma segura. Este problema afecta a las versiones de BIND 9 9.20.0 a 9.20.20, 9.21.0 a 9.21.19, y 9.20.9-S1 a 9.20.20-S1. Las versiones de BIND 9 9.18.0 a 9.18.46 y 9.18.11-S1 a 9.18.46-S1 NO están afectadas.
First Time Isc bind
Isc
References () https://downloads.isc.org/isc/bind9/9.20.21 - () https://downloads.isc.org/isc/bind9/9.20.21 - Patch
References () https://downloads.isc.org/isc/bind9/9.21.20 - () https://downloads.isc.org/isc/bind9/9.21.20 - Patch
References () https://kb.isc.org/docs/cve-2026-3591 - () https://kb.isc.org/docs/cve-2026-3591 - Vendor Advisory

25 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 14:16

Updated : 2026-05-21 15:24


NVD link : CVE-2026-3591

Mitre link : CVE-2026-3591

CVE.ORG link : CVE-2026-3591


JSON object : View

Products Affected

isc

  • bind
CWE
CWE-305

Authentication Bypass by Primary Weakness

CWE-562

Return of Stack Variable Address