Zone Manipulation Vulnerability in BIND by ISC
CVE-2026-78301
What is CVE-2026-78301?
A malformed zone containing NS or DNAME nodes positioned above its origin can lead to unauthorized zone cuts in BIND authoritative servers. If an attacker inserts this malformed zone through a zone transfer, it can compromise the authoritative response for queries within the configured zone, redirecting them to potentially dangerous out-of-zone delegations. In recursion-enabled servers, BIND can cache these attacker-supplied responses, creating vulnerabilities beyond the configured zone. This issue persists as long as the malformed zone remains active in the database, highlighting significant security implications for DNS management.
Affected Version(s)
BIND 9 9.11.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.27
BIND 9 9.21.0 <= 9.21.25
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved