CVE-2026-11622 on CTRL-OS 26.05
Aliases: CVE-2026-11622
Packages: bind
Status: Plausible
Advisory Information
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the
max-cache-sizeparameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Updates
2026-07-23 23:45 CEST
Metadata changes:
- Status for package
bind: “Plausible”
2026-07-23 23:40 CEST
Metadata changes:
- Status for package
bind: “New”