Multiple Bind Vulnerabilities Lead to Denial of Service Risks

Multiple Bind Vulnerabilities Lead to Denial of Service Risks

First seen 27 Aug 2026, 03:38 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in Bind, discovered by researchers Vitaly Simonovich and Shuhan Zhang, could allow remote attackers to exploit memory exhaustion and incorrect DNS message handling, leading to denial of service (DoS) conditions. Specifically, CVE-2026-3039 allows excessive resource usage during GSS-API TKEY negotiation, while CVE-2026-3592 and CVE-2026-5946 involve amplification attacks and crashes due to mishandled DNS messages. These vulnerabilities primarily affect Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. The issues were published on May 20, 2026, and are now addressed in security updates. System administrators are advised to apply the latest patches to mitigate these risks.

Key Points: • Three critical vulnerabilities in Bind could lead to denial of service attacks. • Affected systems include Ubuntu 18.04 LTS and 20.04 LTS. • Patches are available, and immediate updates are recommended.

Timeline

2026-05-20
CVE-2026-3039 published
Vulnerability allows memory exhaustion during GSS-API TKEY negotiation, leading to DoS.
Ubuntu
2026-05-20
CVE-2026-3592 published
Incorrect handling of self-pointed glue records could enable DoS amplification attacks.
Ubuntu
2026-05-20
CVE-2026-5946 published
Improper handling of DNS messages could cause Bind to crash, resulting in DoS.
Ubuntu
2026-08-26
Security patches released
Updates for affected Bind versions were made available to mitigate the vulnerabilities.
Linuxsecurity