Review reviewHigh

CVE-2026-5946

ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21...

CVSS
7.5
EPSS
1.81%
76.1% percentile
CISA KEV
Not listed
Published
2026.05.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.81%
Technical severityCVSS 7.5

Vulnerability overview

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21...

Affected product and versions

Product
ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
Affected versions
>= 9.11.0 <= 9.16.50, >= 9.18.0 <= 9.18.48, >= 9.20.0 <= 9.20.22, >= 9.21.0 <= 9.21.21, >= 9.11.3-S1 <= 9.16.50-S1, >= 9.18.11-S1 <= 9.18.48-S1, >= 9.20.9-S1 <= 9.20.22-S1, >= 9.18.0 < 9.18.49, >= 9.20.0 < 9.20.23, >= 9.21.0 < 9.21.22
Fixed versions
9.18.49, 9.20.23, 9.21.22

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-125, CWE-1287, CWE-20, CWE-617, CWE-754, CWE-843
CVE-2026-5946 — ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 | SECUFOCUS NOW