CVE-2026-11605 PUBLISHED

Unnecessary validation of DNSSEC signed records

Assigner: isc
Reserved: 08.06.2026 Published: 22.07.2026 Updated: 22.07.2026

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor ISC
Product BIND 9
Versions Default: unaffected
  • affected from 9.20.0 to 9.20.24 (incl.)
  • affected from 9.21.0 to 9.21.23 (incl.)
  • affected from 9.20.9-S1 to 9.20.24-S1 (incl.)

Exploits

This flaw was discovered in internal testing. We are not aware of any active exploits.

Workarounds

No workarounds known.

Solutions

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.26, 9.21.24, or 9.20.26-S1.

References

Problem Types

  • CWE-408 Incorrect Behavior Order - Early Amplification CWE

Impacts

  • Exhaustion of CPU resources.