CVE-2026-5950: Unbounded resend loop in BIND 9 resolver
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
Affected Software
Remediation
Information
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5950?
CVE-2026-5950 is classified as a critical severity vulnerability that can lead to severe resource exhaustion.
How do I fix CVE-2026-5950?
To mitigate CVE-2026-5950, upgrade to the latest versions of BIND 9 that address this issue.
What software is affected by CVE-2026-5950?
CVE-2026-5950 affects specific versions of Internet Systems Consortium BIND 9, particularly between 9.18.36 and 9.18.48, among others.
What type of attack does CVE-2026-5950 enable?
CVE-2026-5950 allows remote unauthenticated attackers to exploit the BIND 9 resolver to create an unbounded resend loop, resulting in resource exhaustion.
How can CVE-2026-5950 impact my system?
CVE-2026-5950 can lead to denial of service on affected systems by overwhelming them with continuous query retries.