ISC BIND 9是ISC组织的域名系统服务器。 ISC BIND 9 9.18.0版本及之前版本、9.20.0版本及之前版本、9.21.0版本及之前版本、9.11.3-S1版本及之前版本和9.20.9-S1版本及之前版本存在加密问题漏洞,该漏洞源于BIND可能接受不正确的子区域NSEC3记录作为有效记录,可能导致攻击者伪造经过身份验证的NXDOMAIN响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13321 | 8.6 HIGH | DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field |
| CVE-2026-11605 | 7.5 HIGH | Unnecessary validation of DNSSEC signed records |
| CVE-2026-11331 | 7.5 HIGH | Potential wildcard CNAME RPZ policy bypass |
| CVE-2026-11622 | 7.5 HIGH | Potential memory usage beyond configured limits |
| CVE-2026-11721 | 7.5 HIGH | Cache poisoning possible with label count discrepancy, RRSIG, and wildcards |
| CVE-2026-12617 | 7.5 HIGH | Record ordering based unexpected exit with CNAME or DNAME |
| CVE-2026-13204 | 7.5 HIGH | Unexpected exit in certain situations with NSEC and NSEC3 both present |
| CVE-2026-10822 | 6.5 MEDIUM | Key Record using PRIVATEDNS algorithm may lead to unexpected exit |
No comments yet