CVE-2026-19666
Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path
Description
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
In plain language
AI Act nowBIND 9 DNS servers using DNS64 are vulnerable to being knocked offline remotely; update affected versions promptly.
Unauthenticated network denial of service in BIND 9's DNS64 filter64 path: a malformed authoritative DNS response triggers a use-after-free during name-proof processing and terminates named.
What to do now
- Check whether your BIND 9 resolver has DNS64 enabled and whether it runs an affected release.
- Upgrade to the matching patched BIND 9 release: 9.20.29, 9.21.26, or 9.20.29-S1.
- Restart the DNS service after upgrading and confirm it continues answering DNS requests.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacksen·The Hacker News· Exploited Cisco Identity Services Engine zero-day
- ISC Patches 14 Vulnerabilities in BIND 9 Security Updateen-us·SecurityWeek· Patch BIND 9 ddos-botnet
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSen·The Hacker News· Patch BIND 9 network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-19666 and every CVE in our database. Create a free account — no credit card required.
Create Free Account