hacker-news · Crawled Sep 17, 2026

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Read original article ↗

AI Summary

The Internet Systems Consortium (ISC) released updates for BIND 9, addressing 14 security vulnerabilities, including a high-severity flaw allowing an unauthenticated attacker to crash a DNS-over-HTTPS (DoH) server with a single malformed request. Several other flaws can lead to denial-of-service conditions via crafted DNS queries or responses, memory/CPU exhaustion, or cache poisoning through DNSSEC validation bypasses. The vulnerabilities affect multiple versions of BIND 9 across stable and development branches, with no workarounds available. While ISC reports no known active exploitation, public reproduction tests exist, increasing the risk of future exploitation.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.