AI description
CVE-2026-19666 describes a vulnerability affecting BIND 9 resolvers configured to utilize `dns64`. If an authoritative server provides a specifically malformed answer, the `named` process of the resolver can terminate unexpectedly. This issue also applies to resolvers using `dns64` with the `break-dnssec yes` option enabled. The vulnerability impacts several versions of BIND 9, including 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, and 9.21.0 through 9.21.25, as well as specific versions of BIND 9.11.3-S1 through 9.18.50-S1 and 9.20.9-S1 through 9.20.27-S1. The Internet Systems Consortium (ISC) is the Common Vulnerabilities and Exposures (CVE) Numbering Authority (CNA) for this particular CVE.
- Description
- On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
- Source
- security-officer@isc.org
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- security-officer@isc.org
- CWE-416
- Hype score
- Not currently trending
BIND 9の脆弱性(High: CVE-2026-19666,19667,76163, 77692,80274,81563, 81736, Medium: CVE-2026-19033, 19662, 19668, 19941,75029, 77119, 78301)と修正バージョン(9.20.29, 9.21.26) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://t.co/L
@omokazuki
16 Sept 2026
95 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔴 BIND 9'da iki yeni DoS açığı keşfedildi: CVE-2026-19666 ve CVE-2026-19667. CVE-2026-19666, DNS64 etkin resolver'ları; CVE-2026-19667 ise varsayılan yapılandırmadaki resolver'ları etkileyerek uzaktan named sürecinin çökmesine neden olabiliyor. Public recursive
@ridvanyagli
16 Sept 2026
690 Impressions
2 Retweets
4 Likes
2 Bookmarks
0 Replies
0 Quotes
インターネットを破壊しました BIND 9に2件の脆弱性を報告し、CVE-2026-19666とCVE-2026-19667が採番されました どちらもリゾルバのDoSで CVE-2026-19666はdns64有効時 CVE-2026-19667はデフォルトで影響します CVSSはどちらも7
@fubukiyokiyoki
16 Sept 2026
14832 Impressions
37 Retweets
193 Likes
46 Bookmarks
1 Reply
1 Quote