cbcvebase.
CVE-2026-10822
published 2026-07-22

CVE-2026-10822: If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first…

PriorityP334medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.38%
31.3th percentile
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Affected

8 ranges
VendorProductVersion rangeFixed in
iscbind
iscbind_99.18.0 – 9.18.50
iscbind_99.18.11-S1 – 9.18.50-S1
iscbind_99.20.0 – 9.20.24
iscbind_99.20.9-S1 – 9.20.24-S1
iscbind_99.21.0 – 9.21.23
iscdhcp
ubuntubind9

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_ubuntu6.8MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.