CVE Vulnerabilities

CVE-2026-3592

Incorrect Behavior Order: Early Amplification

Published: May 20, 2026 | Modified: May 21, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Weakness

The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.

Affected Software

NameVendorStart VersionEnd Version
BindIsc9.11.0 (including)9.16.50 (including)
BindIsc9.18.0 (including)9.18.49 (excluding)
BindIsc9.20.0 (including)9.20.23 (excluding)
BindIsc9.21.0 (including)9.21.22 (excluding)
Red Hat Hardened ImagesRedHatbind-main-9.18.49-1.hum1*
Bind9Ubuntudevel*
Bind9Ubuntuesm-infra/xenial*
Bind9Ubuntujammy*
Bind9Ubuntunoble*
Bind9Ubuntuquesting*
Bind9Ubunturesolute*
Bind9Ubuntuupstream*

References