BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039) — Threadlinqs Intelligence
As of 2026-05-30, BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0599 · Severity: HIGH · CVSS: 7.5 · Status: MONITORING · Category: VULNERABILITY
ISC disclosed six remotely exploitable vulnerabilities in BIND 9 on 20 May 2026 (CVE-2026-3593, CVE-2026-5950, CVE-2026-5947, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039), affecting recursive
On 20 May 2026, the Internet Systems Consortium (ISC) publicly disclosed six new CVEs in BIND 9 — the most widely deployed open-source DNS server — and refreshed its centralized BIND 9 Software Vulnerability Matrix to map each CVE to affected and fixed releases. The matrix is the canonical reference operators use to determine exposure; this disclosure adds entries #169 through #174 covering both resolver-side and authoritative-side defects. All six issues are remotely exploitable by unauthenticated attackers, four are rated High by ISC, and two are rated Medium. ISC issued early notifications to subscribers on 13 May 2026 and synchronized public disclosure across all six advisories on 20 May 2026.
CVE-2026-3593 — Heap use-after-free in BIND 9 DNS-over-HTTPS (DoH) implementation (CVSS 7.4, High, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H). A use-after-free condition exists in BIND's DoH code path. An attacker who can reach a DoH-enabled BIND instance with crafted HTTP/2 traffic can trigger memory corruption, which under specific conditions may permit arbitrary code execution; the more likely outcome is named crash and information disclosure from the freed heap region. The flaw affects BIND 9.20.0 → 9.20.22, BIND 9.21.0 → 9.21.21, and Supported Preview 9.20.9-S1 → 9.20.22-S1. The 9.18 branch is not affected. Both authoritative servers and resolvers are vulnerable if they enable DoH listeners. Disabling DoH is an effective mitigation pending patch.
CVE-2026-5947 — SIG(0) validation race condition during query flood (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A race condition between SIG(0) signature validation and the recursive-clients quota produces a use-after-free / dangling-pointer read. When a SIG(0)-signed inbound DNS message is being validated and the recursive-clients limit is simultaneously reached, that same message may be discarded while validation is still reading from its memory. Result: segmentation faults / named aborts. Code execution from the improper read is considered unlikely. Affects BIND 9.20.0 → 9.20.22 and 9.21.0 → 9.21.21; 9.18.28 → 9.18.49 is not affected.
CVE-2026-5950 — Unbounded resend loop in BIND 9 resolver (CVSS 5.3, Medium, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). A defect in the resolver state machine's bad-server handling permits an attacker-induced query pattern to enter a retry loop with no upper bound, exhausting CPU and memory on the resolver and causing sustained denial-of-service across all clients relying on that resolver. The vulnerability is reachable by remote unauthenticated attackers that can induce the target to issue resolution attempts (e.g., by visiting attacker-controlled domains or sending queries that traverse the resolver). Affects 9.18.36 → 9.18.48, 9.20.8 → 9.20.22, 9.21.7 → 9.21.21. No workaround; patch only.
CVE-2026-5946 — Invalid handling of CLASS != IN (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Multiple flaws in named's handling of DNS messages whose CLASS is not Internet (IN) — for example CHAOS or HESIOD, or meta-classes ANY/NONE in the question section. Specially crafted requests reaching recursion, dynamic update (UPDATE), zone-change notification (NOTIFY), or IN-specific record-type processing in non-IN data trigger assertion failures inside named, terminating the daemon and producing denial-of-service. Affects an extraordinarily wide range — 9.11.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21 — encompassing many EoL deployments. Workarounds: avoid configuring non-IN zones and do not expose Dynamic Update interfaces to untrusted networks.
CVE-2026-3592 — Amplification vulnerabilities via self-pointed glue records (CVSS 5.3, Medium, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). A recursive resolver that queries a maliciously authored zone containing glue records that point back into themselves expends disproportionate bandwidth and TCP resources attempting to resolve the name, creating an amplification/exhaustion primitive abusable for
Weaknesses (CWE)
CWE-416, CWE-362, CWE-835, CWE-400, CWE-617, CWE-405, CWE-401, CWE-20
Target sectors: government, financial, healthcare, telecommunications, internet-service-providers, education, technology, cloud-providers, critical-infrastructure, enterprise-it
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-3593, CVE-2026-5947, CVE-2026-5950, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039, T1590, T1590.002, T1595.002, T1583.001, T1583.004, T1583.002, T1587.004, T1190, T1133, T1203