CVE-2026-11605: Unnecessary validation of DNSSEC signed records
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.21.24 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.26-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-10723 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-10822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-11331 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-11605 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-11622 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-11721 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-12617 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-13204 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-13321
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11605?
The severity of CVE-2026-11605 is high, with a CVSS score of 7.5.
What type of vulnerability is CVE-2026-11605?
CVE-2026-11605 is a resource exhaustion vulnerability associated with DNSSEC validation.
How do I fix CVE-2026-11605?
To fix CVE-2026-11605, you should update to the latest version of ISC BIND that addresses this vulnerability.
What software is affected by CVE-2026-11605?
ISC BIND 9 is the software affected by CVE-2026-11605.
What are the consequences of CVE-2026-11605?
CVE-2026-11605 can lead to resource exhaustion, causing the DNS resolver to waste resources on unnecessary RRSIG validation.