CVE-2026-3119Patch(isc / bind)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-25); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-25: 3Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-28: 103-2503-2603-2703-28
Signal classification3 categories
Patch
457.1%
General
228.6%
Disclosure
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-253
General1Patch2
2026-03-262
Disclosure1Patch1
2026-03-271
General1
2026-03-281
Patch1
Full discourse7 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】BIND 9.20.xの脆弱性(DNSサービスの停止)について(CVE-2026-3119) - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-03-26-bind9-vuln-tkey.html

    Post summary

    An advisory announcing CVE-2026-3119, a denial‑of‑service flaw in BIND 9.20.x that stops DNS services, and urging users to upgrade.

    05081852
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    【自分用メモ】今回は4件。 CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation https://kb.isc.org/docs/cve-2026-1519 CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence https://kb.isc.org/docs/cve-2026-3104 CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly https://kb.isc.org/docs/cve-2026-3119 CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The memo lists four 2026 CVEs with concise technical notes and links to ISC knowledge‑base pages, indicating early disclosure of vulnerabilities.

    042711.3K
    4.4K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    SIOSセキュリティブログを更新しました。 BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    The blog post announces BIND 9 CVE vulnerabilities and provides the updated BIND 9 releases that contain patches for those issues.

    03033877
    360 followersView on X
  • Toshifumi Sakaguchi@siskrn
    General

    NSEC3の負荷問題とかTKEYとか。   https://kb.isc.org/docs/cve-2026-1519   https://kb.isc.org/docs/cve-2026-3104   https://kb.isc.org/docs/cve-2026-3119   https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The tweet lists four CVE reference links and briefly mentions DNSSEC-related issues (NSEC3 load and TKEY), but provides no specifics on exploitation, patches, or technical details.

    01040201
    259 followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVEs fixed in BIND 9 CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass

    Post summary

    BIND 9 is releasing a patch for CVE‑2026‑3119 and CVE‑2026‑3591, with concise descriptive details, but no proof‑of‑concept, exploit code, or evidence of current exploitation.

    00010229
    4.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3119 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3119 #CVE-2026-3119 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/mu641Xq8U8

    Post summary

    A brief announcement of CVE-2026-3119 with severity and general product impact, but no technical, exploit, or remediation details.

    0000025
    123 followersView on X
  • IT関連サイト記事@itit7777
    Patch

    IT関連サイト記事が更新されました!記事はこちらから⇒ BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    The article announces BIND 9 update releases that address several CVEs, providing patch information but no exploit or detailed technical content.

    0000065
    448 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more