Memory Consumption Flaw in BIND 9 by ISC
CVE-2026-11622
7.5HIGH
What is CVE-2026-11622?
A vulnerability exists in BIND 9 affecting its DNSSEC validating resolver that can lead to excessive memory utilization during random subdomain attacks. This occurs when an attacker sends validation queries at a rate that outpaces the resolver's processing capability, resulting in memory consumption that far exceeds the limits set by the max-cache-size configuration parameter. As a result, the resolver may become unstable, impacting its performance and the services reliant upon it.
Affected Version(s)
BIND 9 9.11.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.24
BIND 9 9.21.0 <= 9.21.23