Integer Overflow or Wraparound Affecting bind package, versions [9.11.0,9.19.0)[9.20.0,9.20.29)[9.21.0,9.21.26)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.55% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Integer Overflow or Wraparound vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-BIND-20074800
  • published24 Sept 2026
  • disclosed16 Sept 2026
  • creditUnknown

Introduced: 16 Sep 2026

NewCVE-2026-19667  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade bind to version 9.19.0, 9.20.29, 9.21.26 or higher.

Overview

Affected versions of this package are vulnerable to Integer Overflow or Wraparound in the named process when handling a precisely sized negative DNS answer from an attacker-controlled authoritative server. An attacker can cause service disruption by sending a specially crafted DNS negative response that triggers a 16-bit length truncation, resulting in a zero-byte negative cache entry and subsequent process termination. This is only exploitable if the instance is configured as a recursive resolver that queries untrusted authoritative servers.

Workaround

This vulnerability can be mitigated by configuring the service to forward all DNS queries to trusted, non-vulnerable upstream DNS servers, preventing direct interaction with potentially malicious authoritative servers.

CVSS Base Scores

version 4.0
version 3.1