CERT-In Flags 14 High-Severity BIND Flaws Enabling Cache Poisoning and Zone Injection
India's CERT-In published advisory CIVN-2026-0467 on 21 September 2026, identifying 14 high-severity vulnerabilities in ISC BIND that go beyond typical denial-of-service risks. The flaws affect multiple BIND 9 release lines, including versions 9.11.0 through 9.18.50 and 9.20.0 through 9.20.27, among others. Root causes include origin validation errors, insufficient data authenticity checks, and acceptance of untrusted data alongside trusted data — three weakness classes that sit on the integrity boundary. Successful exploitation could allow attackers to poison DNS caches, spoof responses, or inject unauthorized records into authoritative zones, silently misdirecting traffic for an entire domain without triggering obvious alerts. Administrators are advised to apply vendor patches, enable DNSSEC validation, restrict recursive queries to known clients, and monitor for unexpected changes in cached or authoritative DNS data.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in