Potential memory usage beyond configured limits
Summary
| CVE | CVE-2026-11622 |
|---|---|
| State | PUBLISHED |
| Assigner | isc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-22 15:16:51 UTC |
| Updated | 2026-07-22 20:33:11 UTC |
| Description | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-770 | CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ISC | BIND 9 | affected 9.11.0 9.18.50 custom | Not specified |
| CNA | ISC | BIND 9 | affected 9.20.0 9.20.24 custom | Not specified |
| CNA | ISC | BIND 9 | affected 9.21.0 9.21.23 custom | Not specified |
| CNA | ISC | BIND 9 | affected 9.11.3-S1 9.18.50-S1 custom | Not specified |
| CNA | ISC | BIND 9 | affected 9.20.9-S1 9.20.24-S1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kb.isc.org/docs/cve-2026-11622 | [email protected] | kb.isc.org | |
| downloads.isc.org/isc/bind9/9.21.24 | [email protected] | downloads.isc.org | |
| downloads.isc.org/isc/bind9/9.20.26 | [email protected] | downloads.isc.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.26, 9.21.24, or 9.20.26-S1.
Workarounds
CNA: No workarounds known.
Exploits
CNA: This flaw was discovered in internal testing. We are not aware of any active exploits.
There are currently no legacy QID mappings associated with this CVE.