CVE-2026-3591
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.32%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-305, CWE-562
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-3591",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-3591",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-25T14:12:43.295485Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-officer@isc.org",
"affectedData": [
{
"vendor": "ISC",
"product": "BIND 9",
"versions": [
{
"status": "affected",
"version": "9.20.0",
"versionType": "custom",
"lessThanOrEqual": "9.20.20"
},
{
"status": "affected",
"version": "9.21.0",
"versionType": "custom",
"lessThanOrEqual": "9.21.19"
},
{
"status": "affected",
"version": "9.20.9-S1",
"versionType": "custom",
"lessThanOrEqual": "9.20.20-S1"
},
{
"status": "unaffected",
"version": "9.18.0",
"versionType": "custom",
"lessThanOrEqual": "9.18.46"
},
{
"status": "unaffected",
"version": "9.18.11-S1",
"versionType": "custom",
"lessThanOrEqual": "9.18.46-S1"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-25T14:16:37.297",
"references": [
{
"url": "https://downloads.isc.org/isc/bind9/9.20.21",
"tags": [
"Patch"
],
"source": "security-officer@isc.org"
},
{
"url": "https://downloads.isc.org/isc/bind9/9.21.20",
"tags": [
"Patch"
],
"source": "security-officer@isc.org"
},
{
"url": "https://kb.isc.org/docs/cve-2026-3591",
"tags": [
"Vendor Advisory"
],
"source": "security-officer@isc.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"description": [
{
"lang": "en",
"value": "CWE-305"
},
{
"lang": "en",
"value": "CWE-562"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.\nBIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected."
},
{
"lang": "es",
"value": "Una vulnerabilidad de use-after-return existe en el servidor 'named' al manejar consultas DNS firmadas con SIG(0). Usando una solicitud DNS especialmente diseñada, un atacante podría ser capaz de hacer que una ACL haga una coincidencia incorrecta con una dirección IP. En una ACL de permiso predeterminado (negando solo direcciones IP específicas), esto podría llevar a acceso no autorizado. Las ACL de denegación predeterminada deberían fallar de forma segura.\nEste problema afecta a las versiones de BIND 9 9.20.0 a 9.20.20, 9.21.0 a 9.21.19, y 9.20.9-S1 a 9.20.20-S1.\nLas versiones de BIND 9 9.18.0 a 9.18.46 y 9.18.11-S1 a 9.18.46-S1 NO están afectadas."
}
],
"lastModified": "2026-06-17T10:43:50.090",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C0EF5D0-68A6-4E00-985B-523D9B243E49",
"versionEndExcluding": "9.20.21",
"versionStartIncluding": "9.20.0"
},
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1DD0950-5CBD-49B2-8007-5E96B3C4FB1B",
"versionEndExcluding": "9.21.20",
"versionStartIncluding": "9.21.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-officer@isc.org"
}