CVE-2026-19667
Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`
Description
If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
In plain language
AI Act nowIf you run bind 9 versions 9.11.0–9.18.50, 9.20.0–9.20.27, 9.21.0–9.21.25, 9.11.3-S1–9.18.50-S1, or 9.20.9-S1–9.20.27-S1, an outsider can take your DNS service offline, so a typical small business should have IT act promptly.
Unauthenticated remote denial of service in bind 9: a malicious authoritative DNS server can trigger 16-bit length truncation in dns_ncache_add(), creating a zero-byte negative-cache entry that aborts named when read.
What to do now
- Ask IT to check every bind 9 resolver version and whether it can query external authoritative DNS servers.
- Upgrade to the matching patched release: 9.20.29, 9.21.26, or 9.20.29-S1.
- Restart the DNS service after upgrading and confirm normal DNS lookups work.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacksen·The Hacker News· Exploited Cisco Identity Services Engine zero-day
- ISC Patches 14 Vulnerabilities in BIND 9 Security Updateen-us·SecurityWeek· Patch BIND 9 ddos-botnet
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSen·The Hacker News· Patch BIND 9 network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-19667 and every CVE in our database. Create a free account — no credit card required.
Create Free Account