CVE-2026-11331

Published Jul 22, 2026

Last updated 2 months ago

CVSS high 7.5
Dns
Port (53)

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-11331 describes a vulnerability within the BIND 9 software that affects its Response Policy Zone (RPZ) processing. An attacker can exploit this by crafting DNS query names that are excessively long. If a resolver uses RPZ with wildcard CNAME policies, these long query names can trigger a "NAMETOOLONG" error condition during processing. The vulnerability arises because this error condition is not handled correctly by the BIND 9 software. This improper handling can lead to two primary outcomes: either the RPZ rule is defeated, allowing the attacker to bypass intended security policies, or the BIND 9 software may terminate unexpectedly. This issue impacts various versions of BIND 9, including 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23, as well as specific S1 releases.

Description
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Source
security-officer@isc.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security-officer@isc.org
CWE-790

Social media

Hype score
Not currently trending
  1. RHSA-2026:54509 - bind9.16 security update (RHEL8) Security Fix(es): - CVE-2026-11331 - CVE-2026-13321 - CVE-2026-11622 - CVE-2026-11721 - CVE-2026-13204 - CVE-2026-10723 https://t.co/kOxtrR4DW5

    @makopicut

    14 Aug 2026

    65 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  2. الحمدلله قبل عدة أشهر اكتشفت ثغرة في BIND 9 أحد أهم برامج البنية التحتية للـ DNS على الإنترنت حول العالم تم إصلاحها ونشرها رسميًا CVE-2026-11331. أول CVE لي، والقصة كا

    @LaithMshal

    9 Aug 2026

    2467 Impressions

    4 Retweets

    63 Likes

    4 Bookmarks

    5 Replies

    0 Quotes

  3. 【自分用メモ】BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822)と修正バージョン(9.20.26, 9.21.24) https://t.co/W42kxTrGcC

    @OrangeMorishita

    23 Jul 2026

    840 Impressions

    2 Retweets

    8 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://t.co/E6Dlb6UAh9

    @omokazuki

    22 Jul 2026

    282 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨*CVE* CVE-2026-11331 An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition du… https://t.co/Ub3YWxNccI ----- Traducción: CVE-2026-11331 Un … https://t.co/utmtNg

    @infoflowcloud

    22 Jul 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes