High severity7.5NVD Advisory· Published Jul 22, 2026· Updated Jul 22, 2026
CVE-2026-11605
CVE-2026-11605
Description
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/bind&distro=openSUSE%20Tumbleweed
< 9.20.26-160000.1.1+ 1 more
- (no CPE)range: < 9.20.26-160000.1.1
- (no CPE)range: < 9.20.26-1.1
Patches
Vulnerability mechanics
References
3News mentions
1- ISC BIND 9: Nine DNSSEC and Response Handling Flaws Disclosed TogetherVypr Intelligence · Jul 23, 2026