← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

BIND 9 Updates Address 14 Vulnerabilities, Including Critical DoH Crash Flaw

🔄 Updated 6d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ISC released BIND 9.20.29 and 9.21.26.
  • Fourteen security vulnerabilities were addressed.
  • One critical flaw affects DNS-over-HTTPS (DoH).
  • Unauthenticated attackers can crash DoH servers.
  • No workarounds are available for the flaws.

BIND 9 Security Updates Released

The Internet Systems Consortium (ISC) has released security updates for BIND 9, its open-source DNS server software. The updates, BIND 9.20.29 and 9.21.26, address fourteen security vulnerabilities that were disclosed on September 16.

Critical DoH Vulnerability Identified

Among the fourteen flaws, one critical vulnerability, tracked as CVE-2026-77692, affects BIND servers configured to answer DNS-over-HTTPS (DoH). This flaw allows an unauthenticated attacker to crash the server process, named, with a single crafted DoH request. The attack involves sending a request with an invalid SIG(0) signature and then closing the connection prematurely before the server finishes checking the signature.

Scope of Vulnerabilities

Seven of the fourteen vulnerabilities are classified as high-severity, potentially leading to denial-of-service (DoS) conditions through unexpected program exits, memory exhaustion, or resource exhaustion. These can be triggered by various methods, including mismatched NOQNAME proof, QTYPE TKEY queries, malformed answers, SVCB/HTTPS AliasMode records, crafted DoH requests, and negative answers of 65,536 bytes. The remaining seven vulnerabilities are of medium severity.

Affected Versions and Fixes

BIND 9.20.29, on the current stable branch, fixes all fourteen vulnerabilities. BIND 9.21.26, on the development branch, fixes thirteen, as CVE-2026-19662 does not affect version 9.21. A supported preview edition, BIND 9.20.29-S1, also fixes all fourteen. Twelve of the fourteen flaws also impact the older 9.18 branch, up to and including 9.18.50, for which ISC ended support at the end of June and has not released fixes. ISC has not identified any workarounds for these vulnerabilities and is not aware of any active exploitation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Internet Systems Consortium (ISC) released security updates for BIND, its open-source DNS server software, addressing 14 vulnerabilities, including seven high-severity flaws. These vulnerabilities could lead to denial-of-service attacks and other issues, prompting ISC to recommend immediate updates for BIND deployments.

The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to address fourteen security vulnerabilities in its open-source DNS server software. One critical flaw allows an unauthenticated attacker to crash a BIND server configured for DNS-over-HTTPS (DoH) with a single request. These updates are important for maintaining the stability and security of DNS infrastructure globally.