PatchSiren cyber security CVE debrief
CVE-2026-12617 ISC CVE debrief
The CVE record describes an issue with unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records in BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. This issue can cause service disruption and has a high CVSS score of 7.5. Users of affected BIND versions should review and apply patches or mitigations to prevent potential service disruption.
- Vendor
- ISC
- Product
- BIND 9
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1 should review and apply patches or mitigations. Operators, platform administrators, vulnerability management teams, and security teams may be impacted by this issue and should take necessary actions to prevent service disruption.
Technical summary
The issue is caused by the resolver's handling of delayed and/or negatively responded DNAME or CNAME queries alongside A queries. If a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. A similar failure may occur if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME.
Defensive priority
High priority due to potential for service disruption.
Recommended defensive actions
- Review and apply patches or mitigations for BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1
- Monitor for unusual resolver behavior
- Implement compensating controls for DNS query handling
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence is based on official CVE and NVD records, as well as references from the Internet Systems Consortium (ISC). The issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. Limited evidence is available, and defenders should verify the affected scope and apply patches or mitigations accordingly.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T15:16:51.963Z and has not been modified since then.