CVE-2026-5947 is a remotely triggerable use-after-free vulnerability in ISC BIND 9 caused by a race condition in asynchronous SIG(0) signature validation. When BIND receives a DNS message signed with SIG(0), it begins validating the signature asynchronously. If, during that validation window, the server reaches its recursive-clients limit under heavy query load and discards the same message, later processing may dereference state associated with the discarded query, resulting in undefined behavior. The flaw has been described in the resolver path around response-context initialization, where query state was retained without a protective reference-counted attachment, allowing concurrent cancellation and cleanup to free the underlying object before asynchronous continuation code accessed it. Affected versions are BIND 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. The 9.18.28 through 9.18.49 and 9.18.28-S1 through 9.18.49-S1 branches are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in ISC BIND 9 affecting SIG(0) validation under high query loads, potentially causing undefined behavior and service instability.
A use-after-free race condition in BIND 9 that can occur during query floods when the server hits its recursive-clients limit while validating a SIG(0) signature, causing program aborts.
A BIND 9 vulnerability where SIG(0) validation during a query flood may lead to undefined behavior.
A high-severity remote use-after-free vulnerability in BIND 9 triggered during SIG(0) validation under query flood conditions, potentially causing the BIND process to crash due to undefined behavior.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.