Resource Exhaustion Issue in BIND Resolver Affecting ISC
CVE-2026-81563
7.5HIGH
What is CVE-2026-81563?
A vulnerability in the BIND DNS resolver can lead to resource exhaustion when handling an SVCB/HTTPS AliasMode record that references 14 or more SVCB/HTTPS ServiceMode records. This failure to deallocate internal resources may occur repeatedly, ultimately hindering the resolver's ability to perform new recursive lookups. This affects multiple versions of BIND 9, potentially putting systems at risk of service disruption.
Affected Version(s)
BIND 9 9.18.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.27
BIND 9 9.21.0 <= 9.21.25
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
ISC would like to thank Samy Medjahed/Ap4sh for bringing this vulnerability to our attention.