CVE-2026-11622: Potential memory usage beyond configured limits
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the max-cache-size parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.20.26 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.21.24 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.20.26-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11622?
The severity of CVE-2026-11622 is rated high with a score of 7.5.
How does CVE-2026-11622 affect ISC BIND 9?
CVE-2026-11622 causes potential runaway memory usage in ISC BIND 9 due to a DNSSEC validation overload from a random subdomain attack.
How can I mitigate CVE-2026-11622?
To mitigate CVE-2026-11622, ensure your ISC BIND 9 software is updated to the latest version that addresses this vulnerability.
What kind of attack exploits CVE-2026-11622?
CVE-2026-11622 can be exploited through a random subdomain attack against a DNSSEC-signed zone.
Are there any known fixes for CVE-2026-11622?
Yes, the issue can be fixed by applying updates for ISC BIND 9 that patch the vulnerability.