CVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.20.26 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.21.24 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.20.26-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13204?
The severity of CVE-2026-13204 is rated as high with a score of 7.5.
How does CVE-2026-13204 impact ISC BIND 9?
CVE-2026-13204 can cause BIND to exit unexpectedly when validating domain records under specific conditions.
What versions of ISC BIND 9 are affected by CVE-2026-13204?
CVE-2026-13204 affects BIND 9 versions 9.11.0 through 9.18.50 and 9.20.0 through 9.20.x.
How do I fix CVE-2026-13204?
To fix CVE-2026-13204, you should upgrade to the latest version of ISC BIND 9 that resolves this vulnerability.
What conditions lead to the vulnerability in CVE-2026-13204?
The vulnerability occurs when both NSEC and NSEC3 records are present for a domain, but only one type of RRSIG is available for validation.