CVE-2026-10822

EUVD-2026-47705
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.

BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 31.19%
Debian logo
Debian Releases
Debian Product
Codename
bind9
bookworm
vulnerable
bookworm (security)
1:9.18.49-1~deb12u2
fixed
bullseye
not-affected
forky
1:9.20.27-1
fixed
sid
1:9.20.27-2
fixed
trixie
vulnerable
trixie (security)
1:9.20.26-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bind9
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1:9.18.39-0ubuntu0.22.04.5
released
noble
Fixed 1:9.18.39-0ubuntu0.24.04.6
released
resolute
Fixed 1:9.20.24-1ubuntu0.2
released
trusty
needs-triage
xenial
needs-triage
isc-dhcp
bionic
needs-triage
focal
not-affected
jammy
not-affected
noble
needs-triage
resolute
needs-triage
trusty
not-affected
xenial
not-affected
bind9-libs
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bind
suse enterprise sap 15 SP6
9.18.50-150600.3.32.1
fixed
suse enterprise sap 15 SP7
9.20.26-150700.3.29.1
fixed
suse enterprise server 15 SP6
9.18.50-150600.3.32.1
fixed
suse enterprise server 15 SP7
9.20.26-150700.3.29.1
fixed
bind-doc
suse enterprise sap 15 SP6
9.18.50-150600.3.32.1
fixed
suse enterprise sap 15 SP7
9.20.26-150700.3.29.1
fixed
suse enterprise server 15 SP6
9.18.50-150600.3.32.1
fixed
suse enterprise server 15 SP7
9.20.26-150700.3.29.1
fixed
bind-utils
suse enterprise sap 15 SP6
9.18.50-150600.3.32.1
fixed
suse enterprise server 15 SP6
9.18.50-150600.3.32.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
bind
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-chroot
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-debuginfo
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-debugsource
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-devel
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-dnssec-utils
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-dnssec-utils-debuginfo
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-doc
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-libs
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-libs-debuginfo
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-license
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-utils
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
bind-utils-debuginfo
Amazon Linux 2023
32:9.18.50-1.amzn2023.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
bind
Azure Linux 3.0
0:9.20.26-1.azl3
fixed