CVE-2026-33600: Null pointer dereference in RPZ transfer
Published Apr 22, 2026
·Updated
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
Affected Software
4 affected components
ISC BIND
PowerDNS recursor>=5.2.0<5.2.9
PowerDNS recursor>=5.3.0<5.3.6
PowerDNS recursor=5.4.0
Event History
Apr 22, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33600?
The severity of CVE-2026-33600 is classified as critical due to the potential for denial of service.
2
How do I fix CVE-2026-33600?
To fix CVE-2026-33600, upgrade to the latest version of ISC BIND that addresses this vulnerability.
3
What causes the vulnerability CVE-2026-33600?
CVE-2026-33600 is caused by a null pointer dereference due to a missing consistency check in RPZ transfer.
4
What systems are affected by CVE-2026-33600?
CVE-2026-33600 primarily affects ISC BIND DNS software.
5
What are the potential impacts of CVE-2026-33600?
The potential impacts of CVE-2026-33600 include a denial of service, affecting the availability of DNS services.