CVE-2026-5946Patch(isc / bind)

LOWCVSS 7.5 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-20CWE-125CWE-617CWE-754CWE-843CWE-1287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 14 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-06-08)
  • 14 total mentions across 6 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline14 mentions / 6d
01345Mentions · 2026-05-20: 2Mentions · 2026-05-21: 3Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 2Mentions · 2026-06-08: 5Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-08: 5Technical Details · 2026-05-21: 3Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 2Technical Details · 2026-06-08: 505-2005-2105-2305-2405-2506-08
Signal classification3 categories
Patch
750.0%
Disclosure
535.7%
General
214.3%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-05-202
Disclosure1General1
2026-05-213
Disclosure1General1Patch1
2026-05-231
Disclosure1
2026-05-241
Disclosure1
2026-05-252
Disclosure1Patch1
2026-06-085
Patch5
Full discourse14 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-5946) - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-classnotin.html

    Post summary

    The advisory warns of a CVE‑2026‑5946 that can shut down BIND 9.x DNS services and strongly recommends installing the latest patch.

    0911131.1K
    1.3K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    BIND9の脆弱性(High: CVE-2026-3039, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, Medium: CVE-206-3592, CVE-206-5950)と9.18.49, 9.20.23, 9.21.22公開 #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260520/

    Post summary

    The post announces new BIND9 releases that patch several high‑severity CVEs, without providing PoC or exploit details. It functions as a straightforward vulnerability disclosure.

    04020356
    370 followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    General

    https://kb.isc.org/docs/cve-2026-3039 https://kb.isc.org/docs/cve-2026-3592 https://kb.isc.org/docs/cve-2026-3593 https://kb.isc.org/docs/cve-2026-5946 https://kb.isc.org/docs/cve-2026-5947 https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The provided URLs link to ISC knowledge base pages for the listed CVEs but the text itself offers no additional details on exploitation, patches, or technical specifics.

    03120377
    4.5K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BINDに複数脆弱性、DNS運用者は更新確認を】 JVNは、BINDに複数の脆弱性が存在すると公表しました。 対象には CVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950 が含まれ、サービス運用妨害やメモリ破壊につながる可能性が示されています。 DNSは停止時の影響が広範囲に及ぶため、外部公開DNSだけでなく、内部リゾルバや委託先のDNS運用状況も確認が必要です。 日本の組織では、BINDのバージョン、namedの異常終了、SERVFAIL急増、DNS監視と冗長化の状態を週明けに確認したいところです。 #BIND #DNS #JVN #CVE #脆弱性対応 #インフラ運用 #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    JVN announces several BIND CVEs that could lead to service disruption and memory corruption, urging DNS operators to verify updates and monitor BIND status.

    01020318
    3.7K followersView on X
  • 楽守|Rakushu - 人とセキュリティ@rakushu_sec
    Disclosure

    BIND 9に複数脆弱性。DNSは普段見えにくい土台ですが、止まると業務全体に影響します。社内DNSの利用有無と更新計画だけでも確認を。無事は成果。 https://kb.isc.org/docs/cve-2026-5946 #セキュリティ #情シス #製造業 #note

    Post summary

    The text announces multiple vulnerabilities in BIND 9, emphasizing their critical role in DNS infrastructure and advising organizations to check internal DNS usage and update plans. The linked CVE details page provides further information.

    0002044
    39 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24367 - Important: bind security update [RHEL9] https://access.redhat.com/errata/RHSA-2026:24367 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat’s RHSA‑2026:24367 issues a security update for BIND 9, addressing memory exhaustion during GSS‑API TKEY negotiation and a denial‑of‑service vector via crafted DNS messages, providing patches for CVE‑2026‑3039 and CVE‑2026‑5946.

    1000073
    116 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24339 - Important: bind security update [RHEL8] https://access.redhat.com/errata/RHSA-2026:24339 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat issued a critical BIND 9 security update, patching CVE‑2026‑3039 (memory exhaustion) and CVE‑2026‑5946 (DNS‑message‑based DoS).

    1000049
    116 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24338 - Important: bind security update [RHEL10] https://access.redhat.com/errata/RHSA-2026:24338 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat’s RHSA-2026:24338 releases patches for two BIND 9 DNS server vulnerabilities (CVE-2026-3039 and CVE-2026-5946), addressing memory exhaustion and denial-of-service issues.

    1000054
    116 followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:23360 - Important: bind9.16 security update [RHEL8] https://access.redhat.com/errata/RHSA-2026:23360 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    Red Hat’s RHSA-2026:23360 releases important updates for BIND 9 addressing CVE‑2026‑3039 and CVE‑2026‑5946, providing technical details of memory exhaustion and DoS weaknesses and confirming the availability of patches.

    1000091
    116 followersView on X
  • MY TECH BLOG@MyTechBlogJP
    Patch

    【BIND 9 脆弱性情報】2026/5/20、ISC が CVE-2026-5946/5947/5950 を同時公開。修正版 9.18.49 / 9.20.23 へ移行推奨 ・3 件中 2 件が High(CVSS 7.5) ・リゾルバは 3 件すべてが対象 ・マトリクス照合の 3 ステップを解説 https://mytech-blog.com/bind9-vulnerability-matrix/ #BIND9

    Post summary

    ISC released three CVE-2026-5946/5947/5950 vulnerabilities, all high severity, and recommends updating to the patched BIND 9 releases 9.18.49 or 9.20.23.

    01000190
    174 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【ISC BINDに複数脆弱性、DNS可用性への影響に注意】 JVNは、ISC BINDにおける複数の脆弱性を公開しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれ、DoS、メモリ破損、use-after-free、再送信ループなどが想定されています。 DNSはメール、Web、クラウド、認証基盤の前提となるため、停止や遅延が広範な業務影響につながります。特に権威DNS、キャッシュDNS、DNS-over-HTTPSを運用している組織は、対象バージョンと設定を確認する必要があります。 日本のSOCは、BINDのバージョン、namedの異常終了、メモリ使用量、SERVFAIL急増、クエリ遅延を監視し、冗長系を考慮して計画的にアップデートしてください。 #BIND #DNS #JVN #CVE #脆弱性 #サイバーセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    JVN has publicly disclosed multiple CVEs targeting ISC BIND, outlining DoS and memory‑corruption related risks, and recommends users update their BIND installations to mitigate potential impacts.

    00010232
    3.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    General

    JVNVU#99225456: ISC BINDにおける複数の脆弱性(2026年5月) https://jvn.jp/vu/JVNVU99225456/ "遠隔の攻撃者によって、サービス運用妨害(DoS)攻撃を引き起こされる(CVE-2026-3039、CVE-2026-3592、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950)" https://t.co/M7l9Giby22

    Post summary

    The tweet references several ISC BIND CVEs that could enable remote DoS attacks, but provides no PoC, exploit code, patch, or evidence of live exploitation.

    00001206
    3.5K followersView on X
  • まこぴ@makopicut
    Patch

    RHSA-2026:24368 - Important: bind9.18 security update [RHEL9] https://access.redhat.com/errata/RHSA-2026:24368 Security Fix(es): - BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) - Denial of Service via specially crafted DNS messages (CVE-2026-5946)

    Post summary

    The Red Hat advisory reports two BIND 9.18 vulnerabilities and announces a vendor patch. No PoC, exploit code, or active exploitation is mentioned.

    0000068
    116 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BIND 9に複数脆弱性、DNS運用者は更新確認を】 JVNは、ISC BINDにおける複数の脆弱性を公表しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれます。 影響は脆弱性ごとに異なりますが、遠隔攻撃者によるサービス運用妨害、メモリ破損、namedのクラッシュなどが想定されています。権威DNS、キャッシュDNS、DNS-over-HTTPS有効環境など、構成によって確認すべき範囲が変わります。 DNSは障害時の業務影響が大きい基盤です。日本の組織は、BINDのバージョン、namedの再起動履歴、メモリ使用量、DoH設定、パッチ適用可否を早急に確認すべきです。 #BIND #DNS #JVN #脆弱性 #CVE #インフラセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/

    Post summary

    The text announces several new CVEs affecting ISC BIND 9, details potential impacts such as service disruption and memory corruption, and urges operators to verify patch status, but does not provide PoC, exploit code, or evidence of active exploitation.

    00000264
    3.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more