Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-10822— Key Record using PRIVATEDNS algorithm may lead to unexpected exit

CVSS 6.5 · Medium EPSS 0.37% · P30

Affected Version Matrix 5

VendorProductVersion RangeStatus
ISCBIND 99.18.0≤ 9.18.50affected
9.20.0≤ 9.20.24affected
9.21.0≤ 9.21.23affected
9.18.11-S1≤ 9.18.50-S1affected
9.20.9-S1≤ 9.20.24-S1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-10822

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Key Record using PRIVATEDNS algorithm may lead to unexpected exit
Source: CVE Program / CVE List V5
Vulnerability Description
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可达断言
Source: CVE Program / CVE List V5
Vulnerability Title
ISC BIND 9 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ISC BIND 9是ISC组织的域名系统服务器。 ISC BIND 9 9.18.0至9.18.50版本、9.20.0至9.20.24版本、9.21.0至9.21.23版本、9.18.11-S1至9.18.50-S1版本和9.20.9-S1至9.20.24-S1版本存在安全漏洞,该漏洞源于BIND在处理DNS记录中特定无效数据结构时接受无效数据,导致一致性检查失败,可能导致服务中止和退出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ISCBIND 9 9.18.0 ~ 9.18.50 -

II. Public POCs for CVE-2026-10822

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10822

登录查看更多情报信息。

Vendor Advisories for CVE-2026-10822 (2)

Vendor Pages for CVE-2026-10822 (1)

Same Patch Batch · ISC · 2026-07-22 · 9 CVEs total

CVE-2026-133218.6 HIGHDNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-116057.5 HIGHUnnecessary validation of DNSSEC signed records
CVE-2026-113317.5 HIGHPotential wildcard CNAME RPZ policy bypass
CVE-2026-116227.5 HIGHPotential memory usage beyond configured limits
CVE-2026-117217.5 HIGHCache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-126177.5 HIGHRecord ordering based unexpected exit with CNAME or DNAME
CVE-2026-132047.5 HIGHUnexpected exit in certain situations with NSEC and NSEC3 both present
CVE-2026-107236.8 MEDIUMIncorrect acceptance of NSEC3 records

IV. Related Vulnerabilities

V. Comments for CVE-2026-10822

No comments yet


Leave a comment