CVE-2026-5946

Source
https://cve.org/CVERecord?id=CVE-2026-5946
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5946.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-5946
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (2)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (1)
OESA (4)
openSUSE (2)
RHSA (9)
RLSA (5)
ROOT (1)
SUSE (8)
UBUNTU (1)
Related
Published
2026-05-20T13:16:40Z
Modified
2026-09-19T08:08:56Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (IN) — for example, CHAOS or HESIOD, or DNS messages that specify meta-classes (ANY or NONE) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (UPDATE), zone change notifications (NOTIFY), or processing of IN-specific record types in non-IN data — can cause assertion failures in named. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

References

Affected packages

Git / github.com/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://github.com/isc-projects/bind9
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "9.11.0"
        },
        {
            "last_affected":  "9.16.50"
        },
        {
            "introduced":  "9.18.0"
        },
        {
            "fixed":  "9.18.49"
        },
        {
            "introduced":  "9.20.0"
        },
        {
            "fixed":  "9.20.23"
        },
        {
            "introduced":  "9.21.0"
        },
        {
            "fixed":  "9.21.22"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v9.*
v9.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5946.json"

Git / gitlab.isc.org/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://gitlab.isc.org/isc-projects/bind9
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "9.11.0"
        },
        {
            "last_affected":  "9.16.50"
        },
        {
            "introduced":  "9.18.0"
        },
        {
            "fixed":  "9.18.49"
        },
        {
            "introduced":  "9.20.0"
        },
        {
            "fixed":  "9.20.23"
        },
        {
            "introduced":  "9.21.0"
        },
        {
            "fixed":  "9.21.22"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v9.*
v9.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5946.json"