CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
Published May 20, 2026
·Updated
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
Affected Software
7 affected componentsFixes available
ISC BIND 9>=9.0.0<=9.16.50, >=9.18.0<=9.18.48, >=9.20.0<=9.20.22, >=9.21.0<=9.21.21, >=9.9.3-S1<=9.16.50-S1, >=9.18.11-S1<=9.18.48-S1, >=9.20.9-S1<=9.20.22-S1
ISC BIND>=9.0.0<=9.16.50
ISC BIND>=9.18.0<9.18.49
ISC BIND>=9.20.0<9.20.23
ISC BIND>=9.21.0<9.21.22
Microsoft azl3 bind 9.20.21-1
debian/bind9<=1:9.16.50-1~deb11u2, <=1:9.16.50-1~deb11u5, <=1:9.18.47-1~deb12u1, <=1:9.20.21-1~deb13u1
1:9.18.49-1~deb12u11:9.20.23-1~deb13u11:9.20.23-1
Remediation
Information
Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.49, 9.20.23, 9.21.22, 9.18.49-S1, or 9.20.23-S1.
Patch Available
Patch Available
Patch Available
Event History
May 20, 2026
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 21, 2026
Data Sourced
via Launchpad·08:49 PM
Description
May 22, 2026
Data Sourced
via Ubuntu·08:48 PM
RemedyDescriptionSeverityAffected Software
May 23, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Data Sourced
via Debian·08:50 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3039?
CVE-2026-3039 has a high severity due to its potential for memory exhaustion in vulnerable BIND servers.
2
How do I fix CVE-2026-3039?
To fix CVE-2026-3039, upgrade your BIND server to a version that is not affected by this vulnerability.
3
Which versions of BIND 9 are affected by CVE-2026-3039?
CVE-2026-3039 affects BIND 9 versions from 9.0.0 to 9.16.50, 9.18.0 to 9.18.48, 9.20.0 to 9.20.22, and 9.21.0 to 9.21.21.
4
What are the risks associated with CVE-2026-3039?
The primary risk associated with CVE-2026-3039 is denial of service due to excessive memory consumption from processing malicious packets.
5
Is CVE-2026-3039 a remote vulnerability?
Yes, CVE-2026-3039 is a remote vulnerability that can be exploited by attackers sending specially crafted packets.