Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3565 articles · 197874 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-11605PATCHED
isc · bind

Unnecessary validation of DNSSEC signed records

Description

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.

Affected Products

VendorProductVersions
iscbind9.20.0, 9.21.0, 9.20.9-S1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
debiandebian linuxcert_advisory90%
internet systems consortiumbindcert_advisory90%

References

  • https://kb.isc.org/docs/cve-2026-11605(vendor-advisory)
  • https://downloads.isc.org/isc/bind9/9.20.26(patch)
  • https://downloads.isc.org/isc/bind9/9.21.24(patch)

Related News (3 articles)

Tier B
BSI Advisories34d ago
[NEU] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security35d ago
ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
→ No new info (linked only)
Tier C
VulDB35d ago
CVE-2026-11605 | ISC BIND up to 9.20.24/9.20.24-S1/9.21.23 DNSSEC Validation resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://kb.isc.org/docs/cve-2026-11605https://downloads.isc.org/isc/bind9/9.20.26https://downloads.isc.org/isc/bind9/9.21.24
CWECWE-408
PublishedJul 22, 2026
Last enriched35d agov2
Trending Score1
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-13321
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Trending: 2
HIGHCVE-2026-11622
Potential memory usage beyond configured limits
Trending: 1
HIGHCVE-2026-11721
Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
Trending: 1
HIGHCVE-2026-13204
Unexpected exit in certain situations with NSEC and NSEC3 both present
Trending: 1
HIGHCVE-2026-12617
Record ordering based unexpected exit with CNAME or DNAME
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 35d ago
v2Tier C35d ago

Severity corrected from HIGH to CRITICAL based on vendor classification in new source

severitycvssEstimate
via VulDB
v135d ago

Initial creation