CVE-2026-5946 Details
Description
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
A vulnerability exists in ISC BIND 9's `named` component, specifically in versions 9.11.0 prior to 9.16.50, 9.18.0 prior to 9.18.48, 9.20.0 prior to 9.20.22, and 9.21.0 prior to 9.21.21. This vulnerability arises from improper handling of DNS messages that are not in the Internet class, such as those in the CHAOS or HESIOD classes, or messages that use meta-classes like ANY or NONE. When these specially crafted requests are processed through affected code paths—such as recursion, dynamic updates, zone change notifications, or the handling of IN-specific record types in non-IN data—assertion failures can occur, causing the `named` server to terminate unexpectedly. This issue affects both authoritative and resolver instances of BIND 9.
Users can upgrade to BIND 9 versions 9.18.49, 9.20.23, or 9.21.22. For those using BIND Supported Preview Edition, versions 9.18.49-S1, 9.20.23-S1, or 9.21.22-S1 are available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-1287 | Improper Validation of Specified Type of Input | redhat-SADP |
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-617 | Reachable Assertion | [email protected] |
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| isc bind | >= 9.11.0, <= 9.16.50 >= 9.18.0, < 9.18.49 >= 9.20.0, < 9.20.23 >= 9.21.0, < 9.21.22 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | redhat-SADP |
| Sep 10, 2026 | CVE Modified | redhat-SADP |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 20, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 21, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | New CVE Received | [email protected] |