CVE detail
CVE-2026-3119
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- BIND Updates Patch High-Severity VulnerabilitiesSecurityWeek
Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers.
newswww.securityweek.comMar 26, 2026, 1:31 PM - https://kb.isc.org/docs/cve-2026-3119kb.isc.org
No excerpt available.
Vendor Advisorykb.isc.orgMar 25, 2026, 2:16 PM - https://downloads.isc.org/isc/bind9/9.21.20downloads.isc.org
No excerpt available.
Patchdownloads.isc.orgMar 25, 2026, 2:16 PM - https://downloads.isc.org/isc/bind9/9.20.21downloads.isc.org
No excerpt available.
Patchdownloads.isc.orgMar 25, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-5946CVSS 7.5 · High
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that…
- CVE-2023-5679CVSS 7.5 · High
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This iss…
- CVE-2023-5517CVSS 7.5 · High
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver receives…
- CVE-2023-4236CVSS 7.5 · High
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are…
- CVE-2022-3924CVSS 7.5 · High
This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero.…
- CVE-2022-3488CVSS 7.5 · High
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an asse…