CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior
Published May 20, 2026
·Updated
Last updated 22 May 2026
Affected Software
5 affected componentsFixes available
ISC BIND 9>=9.20.0<=9.20.22, >=9.21.0<=9.21.21, >=9.20.9-S1<=9.20.22-S1
ISC BIND>=9.20.0<9.20.23
ISC BIND>=9.21.0<9.21.22
Microsoft azl3 bind 9.20.21-1
debian/bind9<=1:9.20.21-1~deb13u1
1:9.16.50-1~deb11u21:9.16.50-1~deb11u51:9.18.47-1~deb12u11:9.18.49-1~deb12u11:9.20.23-1~deb13u11:9.20.23-1
Remediation
Information
Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.23, 9.21.22, or 9.20.23-S1.
Patch Available
Patch Available
Event History
May 20, 2026
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 21, 2026
Data Sourced
via Launchpad·08:49 PM
Description
May 22, 2026
Data Sourced
via Ubuntu·08:48 PM
RemedyDescriptionSeverityAffected Software
May 23, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Data Sourced
via Debian·08:50 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5947?
CVE-2026-5947 has a severity rating that indicates significant risk due to potential undefined behavior from a use-after-free violation.
2
How do I fix CVE-2026-5947?
To fix CVE-2026-5947, update ISC BIND 9 to version 9.20.23 or later, or 9.21.22 or later.
3
What kind of vulnerability is CVE-2026-5947?
CVE-2026-5947 is a race condition vulnerability that can lead to undefined behavior during SIG(0) validation.
4
Which versions of ISC BIND 9 are affected by CVE-2026-5947?
ISC BIND 9 versions from 9.20.0 to 9.20.22, 9.21.0 to 9.21.21, and 9.20.9-S1 to 9.20.22-S1 are affected by CVE-2026-5947.
5
What impact does CVE-2026-5947 have on system security?
CVE-2026-5947 may allow attackers to exploit the race condition leading to potential system crashes or unauthorized access.