CVE-2026-5947Disclosure(isc / bind)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would occur during a query flood), and that same DNS message is discarded per the limit, there is a brief window of time while the SIG(0) validation may attempt to read the now-discarded DNS message. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.28 through 9.18.49 and 9.18.28-S1 through 9.18.49-S1 are NOT affected.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-362CWE-416CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-05-20); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-05-20: 3Mentions · 2026-05-21: 3Mentions · 2026-05-23: 2Mentions · 2026-05-25: 1Mentions · 2026-06-12: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 3Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-12: 105-2005-2105-2305-2506-12
Signal classification3 categories
Disclosure
550.0%
Patch
330.0%
General
220.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-05-203
Disclosure1General1Patch1
2026-05-213
Disclosure2Patch1
2026-05-232
Disclosure1Patch1
2026-05-251
Disclosure1
2026-06-121
General1
Full discourse10 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】(緊急)BIND 9.20.xの脆弱性(競合状態の発生)について(CVE-2026-5947) - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-sig0.html

    Post summary

    The notice alerts users to a race condition vulnerability (CVE‑2026‑5947) in BIND 9.20.x and urges a patch via a version upgrade.

    02061583
    1.3K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    BIND9の脆弱性(High: CVE-2026-3039, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, Medium: CVE-206-3592, CVE-206-5950)と9.18.49, 9.20.23, 9.21.22公開 #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260520/

    Post summary

    The post announces BIND9 vulnerabilities (CVE‑2026‑3039, ‑3593, ‑5946, ‑5947, ‑206‑3592, ‑206‑5950) and releases patched versions 9.18.49, 9.20.23, and 9.21.22.

    04020356
    370 followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    General

    https://kb.isc.org/docs/cve-2026-3039 https://kb.isc.org/docs/cve-2026-3592 https://kb.isc.org/docs/cve-2026-3593 https://kb.isc.org/docs/cve-2026-5946 https://kb.isc.org/docs/cve-2026-5947 https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The text lists six URLs to ISC knowledge base articles for CVE-2026‑3039, CVE-2026‑3592, CVE-2026‑3593, CVE-2026‑5946, CVE-2026‑5947, and CVE-2026‑5950, but provides no details about exploits, patches, or other specifics.

    03120377
    4.5K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BINDに複数脆弱性、DNS運用者は更新確認を】 JVNは、BINDに複数の脆弱性が存在すると公表しました。 対象には CVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950 が含まれ、サービス運用妨害やメモリ破壊につながる可能性が示されています。 DNSは停止時の影響が広範囲に及ぶため、外部公開DNSだけでなく、内部リゾルバや委託先のDNS運用状況も確認が必要です。 日本の組織では、BINDのバージョン、namedの異常終了、SERVFAIL急増、DNS監視と冗長化の状態を週明けに確認したいところです。 #BIND #DNS #JVN #CVE #脆弱性対応 #インフラ運用 #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    The JVN announcement reports multiple BIND CVEs, highlighting potential service disruption and memory corruption, without providing PoC, exploit, or patch details.

    01020318
    3.7K followersView on X
  • Yu F@fj_twt
    Disclosure

    CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior https://kb.isc.org/docs/cve-2026-5947

    Post summary

    CVE‑2026‑5947 is a newly disclosed vulnerability involving improper SIG(0) validation during query flood, which could trigger undefined behavior; further technical details are available through ISC’s knowledge base.

    02010316
    1.5K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【ISC BINDに複数脆弱性、DNS可用性への影響に注意】 JVNは、ISC BINDにおける複数の脆弱性を公開しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれ、DoS、メモリ破損、use-after-free、再送信ループなどが想定されています。 DNSはメール、Web、クラウド、認証基盤の前提となるため、停止や遅延が広範な業務影響につながります。特に権威DNS、キャッシュDNS、DNS-over-HTTPSを運用している組織は、対象バージョンと設定を確認する必要があります。 日本のSOCは、BINDのバージョン、namedの異常終了、メモリ使用量、SERVFAIL急増、クエリ遅延を監視し、冗長系を考慮して計画的にアップデートしてください。 #BIND #DNS #JVN #CVE #脆弱性 #サイバーセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    JVN announced multiple CVEs affecting ISC BIND, outlining serious DoS and memory‑corruption risks and advising affected operators to verify versions and plan updates.

    00010232
    3.7K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 DNS “availability” bugs are the worst kind: not glamorous RCE, just angry servers under load. Patch CVE-2026-5947 fast—because nothing screams Windows like “network down” on payday. #Windows #Security #DNS #Microsoft https://windowsforum.com/threads/cve-2026-5947-bind-sig-0-race-condition-patch-to-prevent-dns-outages.419419/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #BindSecurity #DnsAvailability https://t.co/7IwyxKO227

    Post summary

    Tweet underscores the urgency of patching CVE‑2026‑5947 to avoid DNS outages, without any evidence of active exploitation or detailed technical information.

    0000176
    1.1K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    JVNVU#99225456: ISC BINDにおける複数の脆弱性(2026年5月) https://jvn.jp/vu/JVNVU99225456/ "遠隔の攻撃者によって、サービス運用妨害(DoS)攻撃を引き起こされる(CVE-2026-3039、CVE-2026-3592、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950)" https://t.co/M7l9Giby22

    Post summary

    The post announces five newly disclosed ISC BIND CVEs that allow remote attackers to trigger DoS attacks, without providing PoC, exploit, or patch information.

    00001206
    3.5K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-5947: BIND 9 Race Condition Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04lckMD0

    Post summary

    The article introduces CVE‑2026‑5947 as a race‑condition issue in BIND 9, focusing on business impact and response strategies without revealing technical exploit or patch details.

    0000024
    31 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BIND 9に複数脆弱性、DNS運用者は更新確認を】 JVNは、ISC BINDにおける複数の脆弱性を公表しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれます。 影響は脆弱性ごとに異なりますが、遠隔攻撃者によるサービス運用妨害、メモリ破損、namedのクラッシュなどが想定されています。権威DNS、キャッシュDNS、DNS-over-HTTPS有効環境など、構成によって確認すべき範囲が変わります。 DNSは障害時の業務影響が大きい基盤です。日本の組織は、BINDのバージョン、namedの再起動履歴、メモリ使用量、DoH設定、パッチ適用可否を早急に確認すべきです。 #BIND #DNS #JVN #脆弱性 #CVE #インフラセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/

    Post summary

    The post announces multiple CVEs affecting ISC BIND 9 and urges Japanese organizations to verify BIND version, restart history, memory usage, DoH settings, and patch status to mitigate potential denial‑of‑service, memory corruption, and crash vulnerabilities.

    00000264
    3.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more