{"id":"CVE-2026-3039","title":"BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets","summary":"BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets.  Typically these servers will be found in …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-771","CWE-770"],"vendor":"isc","product":"bind","affected":["bind >= 9.0.0, <= 9.16.50","bind >= 9.18.0, < 9.18.49","bind >= 9.20.0, < 9.20.23","bind >= 9.21.0, < 9.21.22"],"patched":["bind 9.21.22"],"published":"2026-05-20","updated":"2026-09-17","sourceUpdated":"2026-09-17T12:18:14.290","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3039","references":[{"url":"https://downloads.isc.org/isc/bind9/9.18.49","label":"security-officer@isc.org"},{"url":"https://downloads.isc.org/isc/bind9/9.20.23","label":"security-officer@isc.org"},{"url":"https://downloads.isc.org/isc/bind9/9.21.22","label":"security-officer@isc.org"},{"url":"https://kb.isc.org/docs/cve-2026-3039","label":"security-officer@isc.org"},{"url":"https://access.redhat.com/errata/RHSA-2026:20334","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23360","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24338","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24339","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24367","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24368","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:55441","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:57189","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60383","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:62549","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:65851","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-3039","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479767","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3039.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-3039"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3039"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-05-20T13:42:49.621351Z"},"epss":0.01047,"epssPercentile":0.62215,"ingestedAt":"2026-08-20T17:59:05.581Z","slug":"CVE-2026-3039","body":"## Overview\n\nBIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets.  Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments.\nThis issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.\n\n## Affected\n\n- `bind >= 9.0.0, <= 9.16.50`\n- `bind >= 9.18.0, < 9.18.49`\n- `bind >= 9.20.0, < 9.20.23`\n- `bind >= 9.21.0, < 9.21.22`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bind 9.21.22`\n\n## Vendor advisories\n\n- **RHSA-2026:60383** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60383)\n- **RHSA-2026:62549** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62549)\n- **RHSA-2026:24338** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24338)\n- **RHSA-2026:24339** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24339)\n- **RHSA-2026:23360** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23360)\n- **RHSA-2026:57189** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57189)\n- **RHSA-2026:55441** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-08-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:55441)\n- **RHSA-2026:24367** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24367)\n- **RHSA-2026:24368** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24368)\n- **RHSA-2026:20334** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-05-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:20334)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3039.json)\n- **RHSA-2026:65851** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65851)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}