{
  "threat_severity" : "Important",
  "public_date" : "2026-07-22T00:00:00Z",
  "bugzilla" : {
    "description" : "bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field",
    "id" : "2504166",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2504166"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.6",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-345",
  "details" : [ "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.", "The BIND resolver accepts validly-signed NSEC records where the \"Next Domain Name\" field points outside the signer's zone." ],
  "statement" : "An attacker controlling any DNSSEC-signed zone can craft NSEC records that span into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses (AD=1).",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55437",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "bind-32:9.18.33-15.el10_2.10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60383",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "bind-32:9.11.4-26.P2.el7_9.21"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54509",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "bind9.16-32:9.16.23-0.22.el8_10.12"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54654",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "bind-32:9.11.36-16.el8_10.14"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54654",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "bind-32:9.11.36-16.el8_10.14"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54510",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "bind-32:9.16.23-40.el9_8.8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55442",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "bind9.18-32:9.18.29-14.el9_8.8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57189",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "bind-32:9.16.23-18.el9_4.12"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55441",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "bind-32:9.16.23-31.el9_6.4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.22",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:57362",
    "cpe" : "cpe:/a:redhat:openshift:4.22::el9",
    "package" : "rhcos-4.22.9.8.202608191915-0"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-12T00:00:00Z",
    "advisory" : "RHSA-2026:54071",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "bind-main-9.20.26-0.1.hum1",
    "impact" : "important"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Affected",
    "package_name" : "bind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "dhcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-13321\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13321" ],
  "name" : "CVE-2026-13321",
  "mitigation" : {
    "value" : "Disclaimer: The following mitigation notes are provided as a courtesy, pending the application of an official patch. This content was generated utilizing AI tools in conjunction with data from cmetaxonomy.org. Customers are advised to independently evaluate and test these temporary mitigations within their own infrastructure.\nISC states no workarounds exist. Until patched, restrict the resolver to authorized client networks and deploy separate resolvers per trust zone. Memory hardening and auth controls don't apply — this is a DNS protocol logic error using validly-signed records.",
    "lang" : "en:us"
  },
  "csaw" : false
}