BIND 9 Flaws Allow Unauthenticated DoS via DNS-over-HTTPS
The Internet Systems Consortium (ISC) patched 14 vulnerabilities in BIND 9, including a critical flaw that allows any unauthenticated attacker to crash a DNS server by sending a single malformed DNS-over-HTTPS request — no credentials or prior access required. DNS infrastructure is foundational to nearly all internet-facing services, meaning an exploited crash can cause widespread outages affecting entire networks or organizations. Seven of the flaws carry a High CVSS score of 7.5, indicating significant risk of denial-of-service at scale. This incident highlights how unpatched DNS software becomes an easy, high-impact target, and that even protocol-level features like DoH can introduce new attack surfaces if not carefully hardened and kept up to date.
Tactical Insight
Immediate actions
- Upgrade all BIND 9 instances to version 9.20.29 or 9.21.26 as released by ISC on September 16, 2026.
- Audit all internet-facing DNS servers to confirm which BIND versions are deployed across your environment.
- Temporarily restrict or firewall DNS-over-HTTPS (DoH) endpoints to trusted sources if patching cannot be completed immediately.
Long-term improvements
- Establish an emergency patching SLA (e.g., 24–72 hours) specifically for critical infrastructure components such as DNS, NTP, and DHCP servers.
- Maintain a continuously updated asset inventory that tracks software versions for all network services, enabling rapid scope assessment during vulnerability disclosures.
- Implement network segmentation to isolate DNS resolvers and authoritative servers, limiting blast radius if a crash or compromise occurs.
Detection measures
- Deploy monitoring and alerting on DNS server availability and response times to detect denial-of-service conditions in near real-time.
- Subscribe to ISC security advisories and integrate them into your vulnerability management workflow for automatic triage.
- Enable logging of anomalous DNS-over-HTTPS request patterns, including malformed or oversized requests, to support rapid incident identification.