Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3565 articles · 197874 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-11622PATCHED
isc · bind

Potential memory usage beyond configured limits

Description

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Affected Products

VendorProductVersions
iscbind9.11.0, 9.20.0, 9.21.0, 9.11.3-S1, 9.20.9-S1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
debiandebian linuxcert_advisory90%
internet systems consortiumbindcert_advisory90%

References

  • https://kb.isc.org/docs/cve-2026-11622(vendor-advisory)
  • https://downloads.isc.org/isc/bind9/9.20.26(patch)
  • https://downloads.isc.org/isc/bind9/9.21.24(patch)

Related News (3 articles)

Tier B
BSI Advisories34d ago
[NEU] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security35d ago
ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
→ No new info (linked only)
Tier C
VulDB35d ago
CVE-2026-11622 | ISC BIND 9 up to 9.20.24-S1 DNSSEC Validation max-cache-size resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://kb.isc.org/docs/cve-2026-11622https://downloads.isc.org/isc/bind9/9.20.26https://downloads.isc.org/isc/bind9/9.21.24
CWECWE-770
PublishedJul 22, 2026
Last enriched35d agov2
Trending Score1
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-13321
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Trending: 2
HIGHCVE-2026-11721
Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
Trending: 1
HIGHCVE-2026-13204
Unexpected exit in certain situations with NSEC and NSEC3 both present
Trending: 1
HIGHCVE-2026-11605
Unnecessary validation of DNSSEC signed records
Trending: 1
HIGHCVE-2026-12617
Record ordering based unexpected exit with CNAME or DNAME
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 35d ago
v2Tier C35d ago

Severity updated from HIGH to CRITICAL based on vendor classification in new article.

severity
via VulDB
v135d ago

Initial creation