isc bind CVE-2026-19666 is a vulnerability in ISC BIND
Published on September 16, 2026

Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-19666 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2026-19666 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2026-19666

Want to know whenever a new CVE is published for ISC BIND? stack.watch will email you.

 

Affected Versions

ISC BIND 9: