CVE Vulnerabilities

CVE-2026-5950

Unchecked Input for Loop Condition

Published: May 20, 2026 | Modified: May 21, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Weakness

The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Affected Software

NameVendorStart VersionEnd Version
BindIsc9.18.36 (including)9.18.49 (excluding)
BindIsc9.20.8 (including)9.20.23 (excluding)
BindIsc9.21.7 (including)9.21.21 (excluding)
Red Hat Hardened ImagesRedHatbind-main-9.18.49-1.hum1*
Bind9Ubuntudevel*
Bind9Ubuntuesm-infra/xenial*
Bind9Ubuntujammy*
Bind9Ubuntunoble*
Bind9Ubuntuquesting*
Bind9Ubunturesolute*
Bind9Ubuntuupstream*

Potential Mitigations

References