CVE-2026-3591 Details
Description
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
A use-after-return vulnerability has been identified in the ISC BIND 9 DNS server, specifically in versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. This vulnerability occurs when the server processes DNS queries signed with SIG(0). An attacker can exploit this flaw by sending a specially-crafted DNS request that causes an Access Control List (ACL) to incorrectly match an IP address. In environments using a default-allow ACL, this could result in unauthorized access. Authoritative servers and resolvers are both affected by this vulnerability.
Users can upgrade to BIND 9.20.21, 9.21.20, or 9.20.21-S1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://downloads.isc.org/isc/bind9/9.20.21 | [email protected] | Patch |
| https://downloads.isc.org/isc/bind9/9.21.20 | [email protected] | Patch |
| https://kb.isc.org/docs/cve-2026-3591 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-305 | Authentication Bypass by Primary Weakness | [email protected] |
| CWE-562 | Return of Stack Variable Address | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| isc bind | >= 9.20.0, < 9.20.21 >= 9.21.0, < 9.21.20 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | New CVE Received | [email protected] |