DEV Community

jeffrey
jeffrey

Posted on

Why 14 BIND CVEs Landed at Once: Reading the September 2026 DNS Advisory

Why 14 BIND CVEs Landed at Once: Reading the September 2026 DNS Advisory

CERT-In note CIVN-2026-0467, published 21 September 2026, bundles 14 CVEs against ISC BIND under a single HIGH severity rating. The grouping is the story as much as the individual flaws are: it tells defenders that a maintenance window, not a single emergency patch, is the realistic response.

Vulnerability overview

The note lists CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, and CVE-2026-81736. CERT-In assigns HIGH severity to the set and describes outcomes that include denial of service, security-restriction bypass, spoofing, cache poisoning, and unauthorized modification of DNS zone data.

Mechanism and exploitation conditions

The advisory attributes the defects to a wide set of weakness classes: use-after-free, a numeric truncation error, excessive platform resource consumption within a loop, missing release of memory after its effective lifetime, a reachable assertion, acceptance of extraneous untrusted data with trusted data, null pointer dereference, origin validation error, asymmetric resource consumption (amplification), insufficient verification of data authenticity, and inefficient algorithmic complexity. That breadth is why the CVEs were published together. They were not a single regression introduced in one release; they are the accumulated output of a coordinated audit and hardening cycle across several maintained branches.
Exploitation requires an attacker to deliver specially crafted DNS queries, DNS responses, DNSSEC-related records, zone-transfer data, TKEY requests, SVCB/HTTPS records, or DNS-over-HTTPS requests. In practice that means the affected BIND instance must be reachable and must process the relevant message type. The note does not state that any of the 14 flaws is being exploited in the wild, and it does not publish per-CVE attack prerequisites.

Impact

The impact profile spans availability and integrity. Availability failures are the most visible: a resolver that terminates stops answering for every client behind it. Integrity failures are the more serious long-term risk. Cache poisoning and origin-validation errors let a crafted answer be treated as authoritative, and unauthorized zone data insertion changes what a server publishes. Both can outlive the attack that caused them.

Affected products and scope

Affected releases are BIND 9.11.0 through 9.18.50, BIND 9.20.0 through 9.20.27, BIND 9.21.0 through 9.21.25, BIND Supported Preview Edition 9.11.3-S1 through 9.18.50-S1, and BIND Supported Preview Edition 9.20.9-S1 through 9.20.27-S1. The range covers the 9.11 and 9.16 branches that many enterprises and ISPs still run, the 9.18 and 9.20 stable branches, and the 9.21 development branch. CERT-In does not map individual CVEs to individual releases, so the fixed build for each flaw must be confirmed against ISC's own advisories.

Exposure context

A ZoomEye query for app="ISC BIND" returned 19,364,144 assets. This measures internet-reachable BIND-fingerprinted hosts, not confirmed-vulnerable systems, and it does not separate recursive from authoritative deployments. It does show that the patch batch applies to a very large reachable population.

Remediation and mitigations

Apply the vendor updates cited by CERT-In and use ISC's advisory index to map each CVE to its fixed release. While patching is in progress, restrict recursion to known client networks, require TSIG and explicit peer authorization for zone transfers, disable unused dynamic update, and rate-limit DNS-over-HTTPS endpoints. Watch for resolver restarts and latency spikes, which are the earliest observable signs of the resource-consumption and memory-safety classes in this batch.

References

Top comments (0)