---
id: CVE-2026-3104
title: >-
  A specially crafted domain can be used to cause a memory leak in a BIND
  resolver simply by querying this domain.

  This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through
  9.21.19, and 9.20.9-S1 through 9.20.20-S1.

  BIND 9 …
summary: >-
  A specially crafted domain can be used to cause a memory leak in a BIND
  resolver simply by querying this domain.

  This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through
  9.21.19, and 9.20.9-S1 through 9.20.20-S1.

  BIND 9 …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-772
  - CWE-401
  - CWE-772
vendor: isc
product: bind
affected:
  - 'bind >= 9.20.0, < 9.20.21'
  - 'bind >= 9.21.0, < 9.21.20'
patched:
  - bind 9.21.20
published: '2026-03-25'
updated: '2026-09-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3104'
references:
  - url: 'https://downloads.isc.org/isc/bind9/9.20.21'
    label: security-officer@isc.org
  - url: 'https://downloads.isc.org/isc/bind9/9.21.20'
    label: security-officer@isc.org
  - url: 'https://kb.isc.org/docs/cve-2026-3104'
    label: security-officer@isc.org
  - url: 'https://access.redhat.com/errata/RHSA-2026:6935'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-3104'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2451310'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3104.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00698
epssPercentile: 0.51277
ingestedAt: '2026-09-01T13:27:08.183Z'
---

## Overview

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

## Affected

- `bind >= 9.20.0, < 9.20.21`
- `bind >= 9.21.0, < 9.21.20`

## Remediation

Upgrade past the affected range:

- `bind 9.21.20`
