CVE-2026-3039Patch(isc / bind)

LOWCVSS 7.5 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-771CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 5 mentions on most recent observed day (2026-06-08)
  • 12 total mentions across 4 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline12 mentions / 4d
01345Mentions · 2026-05-20: 3Mentions · 2026-05-21: 3Mentions · 2026-05-25: 1Mentions · 2026-06-08: 5Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-06-08: 5Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 3Technical Details · 2026-05-25: 1Technical Details · 2026-06-08: 505-2005-2105-2506-08
Signal classification3 categories
Patch
758.3%
Disclosure
433.3%
General
18.3%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-05-203
Disclosure2General1
2026-05-213
Disclosure1Patch2
2026-05-251
Disclosure1
2026-06-085
Patch5
Full discourse12 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】(緊急)BIND 9.xの脆弱性(メモリ不足の発生)について(CVE-2026-3039) - バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-gssapitkey.html

    Post summary

    The post alerts users to a memory exhaustion vulnerability in BIND 9.x (CVE‑2026‑3039) and strongly recommends upgrading to address the risk, with no evidence of active exploitation or PoC details.

    02051776
    1.3K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    BIND9の脆弱性(High: CVE-2026-3039, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, Medium: CVE-206-3592, CVE-206-5950)と9.18.49, 9.20.23, 9.21.22公開 #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260520/

    Post summary

    The advisory announces that several BIND9 CVEs (CVE-2026-3039, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, CVE-206-3592, CVE-206-5950) have been disclosed and that updated versions 9.18.49, 9.20.23, and 9.21.22 are now available, but it provides no proof‑of‑concept, exploit code, or evidence of active exploitation.

    04020356
    370 followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    General

    https://kb.isc.org/docs/cve-2026-3039 https://kb.isc.org/docs/cve-2026-3592 https://kb.isc.org/docs/cve-2026-3593 https://kb.isc.org/docs/cve-2026-5946 https://kb.isc.org/docs/cve-2026-5947 https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The input consists solely of links to ISC advisory pages without any accompanying details or claims about PoCs, exploits, or patches.

    03120377
    4.5K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BINDに複数脆弱性、DNS運用者は更新確認を】 JVNは、BINDに複数の脆弱性が存在すると公表しました。 対象には CVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950 が含まれ、サービス運用妨害やメモリ破壊につながる可能性が示されています。 DNSは停止時の影響が広範囲に及ぶため、外部公開DNSだけでなく、内部リゾルバや委託先のDNS運用状況も確認が必要です。 日本の組織では、BINDのバージョン、namedの異常終了、SERVFAIL急増、DNS監視と冗長化の状態を週明けに確認したいところです。 #BIND #DNS #JVN #CVE #脆弱性対応 #インフラ運用 #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    JVN reports several CVEs affecting BIND, warning of possible service disruption and memory corruption, but no PoC, exploit, patch or active exploitation details are given.

    01020318
    3.7K followersView on X
  • Yu F@fj_twt
    Disclosure

    CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation https://kb.isc.org/docs/cve-2026-3039

    Post summary

    ISC has disclosed a memory exhaustion vulnerability in BIND 9 that occurs during GSS‑API TKEY negotiation.

    01020298
    1.6K followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24367 - Important: bind security update [RHEL9] https://access.redhat.com/errata/RHSA-2026:24367 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    This erratum announces security fixes for two BIND 9 vulnerabilities: a memory exhaustion flaw in GSS-API TKEY negotiation (CVE-2026-3039) and a denial‑of‑service vulnerability via crafted DNS messages (CVE-2026-5946). The updates are available through RHSA-2026:24367.

    1000073
    116 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24339 - Important: bind security update [RHEL8] https://access.redhat.com/errata/RHSA-2026:24339 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat issued updates to address two BIND 9 vulnerabilities: CVE-2026-3039 (memory‑exhaustion via GSS‑API TKEY) and CVE-2026-5946 (DoS via crafted DNS messages).

    1000049
    116 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24338 - Important: bind security update [RHEL10] https://access.redhat.com/errata/RHSA-2026:24338 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat released an errata update (RHSA‑2026:24338) that patches two BIND 9 vulnerabilities—one causing memory exhaustion during GSS‑API TKEY negotiation, the other a DoS via crafted DNS messages—providing a definitive fix for RHEL10 users.

    1000054
    116 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:23360 - Important: bind9.16 security update [RHEL8] https://access.redhat.com/errata/RHSA-2026:23360 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat issues security updates for BIND 9.16, addressing CVE‑2026‑3039 (memory exhaustion) and CVE‑2026‑5946 (DNS‑based denial of service).

    1000091
    116 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    JVNVU#99225456: ISC BINDにおける複数の脆弱性(2026年5月) https://jvn.jp/vu/JVNVU99225456/ "遠隔の攻撃者によって、サービス運用妨害(DoS)攻撃を引き起こされる(CVE-2026-3039、CVE-2026-3592、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950)" https://t.co/M7l9Giby22

    Post summary

    ISC BIND has disclosed multiple CVEs (CVE-2026-3039, 3592, 5946, 5947, 5950) that enable remote attackers to perform DoS attacks; no PoC, exploit code, patch, or active exploitation is reported.

    00001206
    3.5K followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24368 - Important: bind9.18 security update [RHEL9] https://access.redhat.com/errata/RHSA-2026:24368 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    This Red Hat Security Advisory (RHSA‑2026:24368) announces a BIND 9.18 update that fixes two CVEs—memory exhaustion in GSS-API TKEY negotiation (CVE‑2026‑3039) and a DNS-based denial-of-service (CVE‑2026‑5946)—and confirms that the relevant patches are available.

    0000068
    116 followersView on X
  • 珈琲好き@likecoffee
    Patch

    (緊急)BIND 9.xの脆弱性(メモリ不足の発生)について(CVE-2026-3039) - バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-gssapitkey.html #%E6%8A%80%E8%A1%93%E7%B3%BB-%E8%B3%87%E6%96%99 #feedly

    Post summary

    The tweet alerts of a memory exhaustion flaw in BIND 9.x (CVE-2026-3039) and strongly urges users to upgrade to mitigate the risk.

    0000064
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more