CVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set synth-from-dnssec yes; (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.21.24 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.26-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11721?
CVE-2026-11721 has a high severity rating of 7.5.
How do I fix CVE-2026-11721?
To fix CVE-2026-11721, update to ISC BIND version 9.20.26 or later.
What are the potential risks associated with CVE-2026-11721?
CVE-2026-11721 can lead to cache poisoning due to a discrepancy in label counts in RRSIG responses.
Which software is affected by CVE-2026-11721?
CVE-2026-11721 affects ISC BIND 9.
What is the primary impact of CVE-2026-11721 on DNS queries?
The primary impact of CVE-2026-11721 is that it can cause `named` to generate incorrect wildcard names, potentially leading to cache poisoning.