Back to all lessons
Awareness Lessons
3 weeks ago

BIND 9 Flaws Allow Unauthenticated DoS via DNS-over-HTTPS

The Internet Systems Consortium (ISC) patched 14 vulnerabilities in BIND 9, including a critical flaw that allows any unauthenticated attacker to crash a DNS server by sending a single malformed DNS-over-HTTPS request — no credentials or prior access required. DNS infrastructure is foundational to nearly all internet-facing services, meaning an exploited crash can cause widespread outages affecting entire networks or organizations. Seven of the flaws carry a High CVSS score of 7.5, indicating significant risk of denial-of-service at scale. This incident highlights how unpatched DNS software becomes an easy, high-impact target, and that even protocol-level features like DoH can introduce new attack surfaces if not carefully hardened and kept up to date.

Tactical Insight

Immediate actions

  • Upgrade all BIND 9 instances to version 9.20.29 or 9.21.26 as released by ISC on September 16, 2026.
  • Audit all internet-facing DNS servers to confirm which BIND versions are deployed across your environment.
  • Temporarily restrict or firewall DNS-over-HTTPS (DoH) endpoints to trusted sources if patching cannot be completed immediately.

Long-term improvements

  • Establish an emergency patching SLA (e.g., 24–72 hours) specifically for critical infrastructure components such as DNS, NTP, and DHCP servers.
  • Maintain a continuously updated asset inventory that tracks software versions for all network services, enabling rapid scope assessment during vulnerability disclosures.
  • Implement network segmentation to isolate DNS resolvers and authoritative servers, limiting blast radius if a crash or compromise occurs.

Detection measures

  • Deploy monitoring and alerting on DNS server availability and response times to detect denial-of-service conditions in near real-time.
  • Subscribe to ISC security advisories and integrate them into your vulnerability management workflow for automatic triage.
  • Enable logging of anomalous DNS-over-HTTPS request patterns, including malformed or oversized requests, to support rapid incident identification.