# BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)

> ISC disclosed six remotely exploitable vulnerabilities in BIND 9 on 20 May 2026 (CVE-2026-3593, CVE-2026-5950, CVE-2026-5947, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039), affecting recursive resolvers and authoritative name servers across the 9.11, 9.16, 9.18, 9.20, and 9.21 branches. Impacts span heap use-after-free in DNS-over-HTTPS (potential memory corruption / RCE), SIG(0) race-condition UAF, unbounded resolver resend loops, assertion-failure crashes on non-IN classes, query amplification via self-pointed glue records, and GSS-API TKEY-driven memory exhaustion. ISC has released fixed versions 9.18.49, 9.20.23, and 9.21.22; no in-the-wild exploitation has been reported.

- **Published:** 2026-05-27T00:00:00Z
- **Last reviewed:** 2026-05-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0599
- **ID:** TL-2026-0599
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3593, CVE-2026-5947, CVE-2026-5950, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039

## Description

On 20 May 2026, the Internet Systems Consortium (ISC) publicly disclosed six new CVEs in BIND 9 — the most widely deployed open-source DNS server — and refreshed its centralized BIND 9 Software Vulnerability Matrix to map each CVE to affected and fixed releases. The matrix is the canonical reference operators use to determine exposure; this disclosure adds entries #169 through #174 covering both resolver-side and authoritative-side defects. All six issues are remotely exploitable by unauthenticated attackers, four are rated High by ISC, and two are rated Medium. ISC issued early notifications to subscribers on 13 May 2026 and synchronized public disclosure across all six advisories on 20 May 2026.

CVE-2026-3593 — Heap use-after-free in BIND 9 DNS-over-HTTPS (DoH) implementation (CVSS 7.4, High, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H). A use-after-free condition exists in BIND's DoH code path. An attacker who can reach a DoH-enabled BIND instance with crafted HTTP/2 traffic can trigger memory corruption, which under specific conditions may permit arbitrary code execution; the more likely outcome is named crash and information disclosure from the freed heap region. The flaw affects BIND 9.20.0 → 9.20.22, BIND 9.21.0 → 9.21.21, and Supported Preview 9.20.9-S1 → 9.20.22-S1. The 9.18 branch is not affected. Both authoritative servers and resolvers are vulnerable if they enable DoH listeners. Disabling DoH is an effective mitigation pending patch.

CVE-2026-5947 — SIG(0) validation race condition during query flood (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A race condition between SIG(0) signature validation and the recursive-clients quota produces a use-after-free / dangling-pointer read. When a SIG(0)-signed inbound DNS message is being validated and the recursive-clients limit is simultaneously reached, that same message may be discarded while validation is still reading from its memory. Result: segmentation faults / named aborts. Code execution from the improper read is considered unlikely. Affects BIND 9.20.0 → 9.20.22 and 9.21.0 → 9.21.21; 9.18.28 → 9.18.49 is not affected.

CVE-2026-5950 — Unbounded resend loop in BIND 9 resolver (CVSS 5.3, Medium, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). A defect in the resolver state machine's bad-server handling permits an attacker-induced query pattern to enter a retry loop with no upper bound, exhausting CPU and memory on the resolver and causing sustained denial-of-service across all clients relying on that resolver. The vulnerability is reachable by remote unauthenticated attackers that can induce the target to issue resolution attempts (e.g., by visiting attacker-controlled domains or sending queries that traverse the resolver). Affects 9.18.36 → 9.18.48, 9.20.8 → 9.20.22, 9.21.7 → 9.21.21. No workaround; patch only.

CVE-2026-5946 — Invalid handling of CLASS != IN (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Multiple flaws in named's handling of DNS messages whose CLASS is not Internet (IN) — for example CHAOS or HESIOD, or meta-classes ANY/NONE in the question section. Specially crafted requests reaching recursion, dynamic update (UPDATE), zone-change notification (NOTIFY), or IN-specific record-type processing in non-IN data trigger assertion failures inside named, terminating the daemon and producing denial-of-service. Affects an extraordinarily wide range — 9.11.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21 — encompassing many EoL deployments. Workarounds: avoid configuring non-IN zones and do not expose Dynamic Update interfaces to untrusted networks.

CVE-2026-3592 — Amplification vulnerabilities via self-pointed glue records (CVSS 5.3, Medium, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). A recursive resolver that queries a maliciously authored zone containing glue records that point back into themselves expends disproportionate bandwidth and TCP resources attempting to resolve the name, creating an amplification/exhaustion primitive abusable for reflected DDoS. Authoritative-only servers that do not perform recursion are believed unaffected. Affects 9.11.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21.

CVE-2026-3039 — Memory exhaustion during GSS-API TKEY negotiation (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). BIND servers configured for TKEY-based GSS-API authentication (typically Active Directory-integrated DNS or Kerberos-secured environments) leak memory on processing maliciously constructed TKEY packets. Sustained packet streams will drive named to OOM termination. Affects 9.0.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21 — and ISC explicitly states all EoL versions are presumed vulnerable. No workaround.

Operational picture: BIND 9 underpins resolution for enterprise networks, ISPs, ccTLD/gTLD operators, AD-integrated forests, and embedded appliances. DoH listeners (CVE-2026-3593) are increasingly enabled on resolver fleets serving privacy-sensitive clients; AD-DNS deployments (CVE-2026-3039) are common across Windows enterprise estates; recursive resolvers exposed to client queries (CVE-2026-5950, CVE-2026-3592) cover the broad ISP and corporate base. Attackers do not need privileged access — every issue is exploitable from a network position that can reach the affected listener, and the resend-loop and CLASS!=IN issues can be triggered by indirect means (visiting a malicious URL, prompting a recursive lookup). No active exploitation has been observed at disclosure, but the disclosure detail (especially the DoH heap UAF and the SIG(0) UAF) gives capable actors enough surface area to build reliable triggers. Operators on 9.20.x and 9.21.x are the highest-risk population because they are vulnerable to the largest number of these CVEs simultaneously.

## MITRE ATT&CK

- T1590 Gather Victim Network Information
- T1590.002 Gather Victim Network Information: DNS
- T1595.002 Active Scanning: Vulnerability Scanning
- T1583.001 Acquire Infrastructure: Domains
- T1583.004 Acquire Infrastructure: Server
- T1583.002 Acquire Infrastructure: DNS Server
- T1587.004 Develop Capabilities: Exploits
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1203 Exploitation for Client Execution
- T1027 Obfuscated Files or Information
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1499 Endpoint Denial of Service
- T1499.003 Endpoint Denial of Service: Application Exhaustion Flood
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1498 Network Denial of Service
- T1498.002 Network Denial of Service: Reflection Amplification
- T1489 Service Stop
- T1496 Resource Hijacking

## Sources

- [ISC BIND 9 Software Vulnerability Matrix (aa-00913)](https://kb.isc.org/docs/aa-00913)
- [CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation](https://kb.isc.org/docs/cve-2026-3593)
- [CVE-2026-5950: Unbounded resend loop in BIND 9 resolver](https://kb.isc.org/docs/cve-2026-5950)
- [CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior](https://kb.isc.org/docs/cve-2026-5947)
- [CVE-2026-5946: Invalid handling of CLASS != IN](https://kb.isc.org/docs/cve-2026-5946)
- [CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records](https://kb.isc.org/docs/cve-2026-3592)
- [CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation](https://kb.isc.org/docs/cve-2026-3039)
- [BIND 9 Software Vulnerabilities Exposes Resolvers and Authoritative Servers to Remote Exploits](https://cybersecuritynews.com/bind-9-vulnerabilities-exposes/)
- [CVE Record: CVE-2026-3593](https://www.cve.org/CVERecord?id=CVE-2026-3593)
- [CVE Record: CVE-2026-5950](https://www.cve.org/CVERecord?id=CVE-2026-5950)
- [CVE Record: CVE-2026-5947](https://www.cve.org/CVERecord?id=CVE-2026-5947)
- [CVE Record: CVE-2026-5946](https://www.cve.org/CVERecord?id=CVE-2026-5946)
- [CVE Record: CVE-2026-3592](https://www.cve.org/CVERecord?id=CVE-2026-3592)
- [CVE Record: CVE-2026-3039](https://www.cve.org/CVERecord?id=CVE-2026-3039)
- [ISC Software Defect and Security Vulnerability Disclosure Policy](https://kb.isc.org/docs/aa-00861)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0599
