An inapplicable NSEC record may be accepted by a `named`...
Moderate severity
Unreviewed
Published
Sep 16, 2026
to the GitHub Advisory Database
•
Updated Sep 16, 2026
Description
Published by the National Vulnerability Database
Sep 16, 2026
Published to the GitHub Advisory Database
Sep 16, 2026
Last updated
Sep 16, 2026
An inapplicable NSEC record may be accepted by a
namedresolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record.This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
References