ISC BIND 9是ISC组织的域名系统服务器。 ISC BIND 9 9.11.0版本至9.18.50版本、9.20.0版本至9.20.24版本、9.21.0版本至9.21.23版本、9.11.3-S1版本至9.18.50-S1版本和9.20.9-S1版本至9.20.24-S1版本存在输入验证错误漏洞,该漏洞源于RRSIG的标签数量小于所在区域的标签数量,导致named为区域产生比攻击者区域更短的通配符名称,可能导致缓存中毒。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13321 | 8.6 HIGH | DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field |
| CVE-2026-11605 | 7.5 HIGH | Unnecessary validation of DNSSEC signed records |
| CVE-2026-11331 | 7.5 HIGH | Potential wildcard CNAME RPZ policy bypass |
| CVE-2026-11622 | 7.5 HIGH | Potential memory usage beyond configured limits |
| CVE-2026-12617 | 7.5 HIGH | Record ordering based unexpected exit with CNAME or DNAME |
| CVE-2026-13204 | 7.5 HIGH | Unexpected exit in certain situations with NSEC and NSEC3 both present |
| CVE-2026-10723 | 6.8 MEDIUM | Incorrect acceptance of NSEC3 records |
| CVE-2026-10822 | 6.5 MEDIUM | Key Record using PRIVATEDNS algorithm may lead to unexpected exit |
No comments yet