{
  "threat_severity" : "Important",
  "public_date" : "2026-05-21T12:32:55Z",
  "bugzilla" : {
    "description" : "bind: BIND: Denial of Service via specially crafted DNS messages",
    "id" : "2479771",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2479771"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-1287",
  "details" : [ "Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`.\nThis issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.", "A flaw was found in the bind component, specifically within the `named` daemon. This vulnerability allows a remote attacker to send specially crafted Domain Name System (DNS) messages. These messages, which use unusual classes or meta-classes, can trigger assertion failures in the `named` daemon when processed. Successful exploitation leads to an application level Denial of Service (DoS), making the DNS service unavailable." ],
  "statement" : "This is rated as an Important denial of service vulnerability. The `named` daemon is susceptible to crashes when processing specially crafted DNS messages that utilize non-Internet (IN) classes or meta-classes. This can lead to service unavailability if an attacker sends malicious requests targeting recursion, dynamic updates, zone change notifications, or specific record type processing.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-08T00:00:00Z",
    "advisory" : "RHSA-2026:24338",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "bind-32:9.18.33-15.el10_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60383",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "bind-32:9.11.4-26.P2.el7_9.21"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-04T00:00:00Z",
    "advisory" : "RHSA-2026:23360",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "bind9.16-32:9.16.23-0.22.el8_10.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-08T00:00:00Z",
    "advisory" : "RHSA-2026:24339",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "bind-32:9.11.36-16.el8_10.8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-08T00:00:00Z",
    "advisory" : "RHSA-2026:24339",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "bind-32:9.11.36-16.el8_10.8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-08T00:00:00Z",
    "advisory" : "RHSA-2026:24367",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "bind-32:9.16.23-40.el9_8.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-08T00:00:00Z",
    "advisory" : "RHSA-2026:24368",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "bind9.18-32:9.18.29-14.el9_8.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57189",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "bind-32:9.16.23-18.el9_4.12"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55441",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "bind-32:9.16.23-31.el9_6.4"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-05-21T00:00:00Z",
    "advisory" : "RHSA-2026:20334",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "bind-main-9.18.49-1.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Affected",
    "package_name" : "bind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "dhcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-5946\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5946" ],
  "name" : "CVE-2026-5946",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}