PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12617 ISC CVE debrief

The CVE record describes an issue with unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records in BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. This issue can cause service disruption and has a high CVSS score of 7.5. Users of affected BIND versions should review and apply patches or mitigations to prevent potential service disruption.

Vendor
ISC
Product
BIND 9
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1 should review and apply patches or mitigations. Operators, platform administrators, vulnerability management teams, and security teams may be impacted by this issue and should take necessary actions to prevent service disruption.

Technical summary

The issue is caused by the resolver's handling of delayed and/or negatively responded DNAME or CNAME queries alongside A queries. If a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. A similar failure may occur if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME.

Defensive priority

High priority due to potential for service disruption.

Recommended defensive actions

  • Review and apply patches or mitigations for BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1
  • Monitor for unusual resolver behavior
  • Implement compensating controls for DNS query handling
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence is based on official CVE and NVD records, as well as references from the Internet Systems Consortium (ISC). The issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. Limited evidence is available, and defenders should verify the affected scope and apply patches or mitigations accordingly.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T15:16:51.963Z and has not been modified since then.