CVE-2026-3039

Source
https://cve.org/CVERecord?id=CVE-2026-3039
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3039.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-3039
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (3)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (1)
OESA (4)
openSUSE (2)
RHSA (9)
RLSA (5)
ROOT (1)
SUSE (8)
UBUNTU (1)
Related
Published
2026-05-20T13:16:23Z
Modified
2026-09-19T08:14:23Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

References

Affected packages

Git / github.com/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://github.com/isc-projects/bind9
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "9.0.0"
        },
        {
            "last_affected":  "9.16.50"
        },
        {
            "introduced":  "9.18.0"
        },
        {
            "fixed":  "9.18.49"
        },
        {
            "introduced":  "9.20.0"
        },
        {
            "fixed":  "9.20.23"
        },
        {
            "introduced":  "9.21.0"
        },
        {
            "fixed":  "9.21.22"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v9.*
v9.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3039.json"

Git / gitlab.isc.org/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://gitlab.isc.org/isc-projects/bind9
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "9.0.0"
        },
        {
            "last_affected":  "9.16.50"
        },
        {
            "introduced":  "9.18.0"
        },
        {
            "fixed":  "9.18.49"
        },
        {
            "introduced":  "9.20.0"
        },
        {
            "fixed":  "9.20.23"
        },
        {
            "introduced":  "9.21.0"
        },
        {
            "fixed":  "9.21.22"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v9.*
v9.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3039.json"