ISC disclosed CVE-2026-5947, a remotely exploitable use-after-free flaw in the BIND 9 recursive resolver that can crash the named process during SIG(0) signature validation. The bug stems from a race condition between asynchronous signature verification and recursive query cancellation when the recursive-clients quota is exhausted, allowing a resquery_t object to be freed while callback code still dereferences it. ISC rated the issue CVSS 7.5 and said the demonstrated impact is denial of service, while arbitrary code execution is considered unlikely.
The vulnerability affects BIND 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1; the 9.18.x ESV branch is not affected because it does not use the asynchronous SIG(0) verification path. According to ISC, no authentication is required, and exploitation is possible if an attacker controls an authoritative server or forwarder that returns SIG(0)-signed responses under query-flood conditions. Fixes were released in 9.20.23, 9.21.22, and 9.20.23-S1, replacing the raw pointer handling with reference-counted attachment and corresponding detach logic.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Fixes for CVE-2026-5947 were released in BIND 9.20.23, 9.21.22, and 9.20.23-S1. The remediation replaced a raw resquery_t pointer with a reference-counted attachment and added matching detach calls.
ISC publicly disclosed CVE-2026-5947, a remotely exploitable denial-of-service flaw in BIND 9 caused by a SIG(0) validation race condition leading to a use-after-free in named. The disclosure rated the issue CVSS 7.5 and noted that arbitrary code execution was considered unlikely.
An ISC GitLab issue documented a heap use-after-free in BIND's recursive resolver caused by a race between asynchronous SIG(0) verification and recursive query cancellation under recursive-clients exhaustion. The issue described remote denial-of-service impact and proposed a fix using reference-counted resquery attachments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcegitlab.isc.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.