CVE-2026-11605 Details
Description
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.
A resource exhaustion vulnerability has been identified in ISC BIND 9, specifically in versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1. This vulnerability arises from the DNSSEC validation process, where BIND unnecessarily validates all RRSIG records in a response, even those that are not needed. When a query to an authoritative server returns a large number of valid but unnecessary RRSIG records, it can lead to a significant and disproportionate increase in CPU usage, causing resource exhaustion.
Users can upgrade to BIND 9.20.26, 9.21.24, or 9.20.26-S1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://downloads.isc.org/isc/bind9/9.20.26 | [email protected] | |
| https://downloads.isc.org/isc/bind9/9.21.24 | [email protected] | |
| https://kb.isc.org/docs/cve-2026-11605 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-408 | Incorrect Behavior Order: Early Amplification | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |