Multiple flaws have been identified in `named` related to...
High severity
Unreviewed
Published
May 20, 2026
to the GitHub Advisory Database
•
Updated May 20, 2026
Description
Published by the National Vulnerability Database
May 20, 2026
Published to the GitHub Advisory Database
May 20, 2026
Last updated
May 20, 2026
Multiple flaws have been identified in
namedrelated to the handling of DNS messages whose CLASS is not Internet (IN) — for example,CHAOSorHESIOD, or DNS messages that specify meta-classes (ANYorNONE) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (UPDATE), zone change notifications (NOTIFY), or processing ofIN-specific record types in non-INdata — can cause assertion failures innamed.This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
References