Cache Poisoning and Zone Injection: The Integrity Risks in the September 2026 BIND Advisory
Cache Poisoning and Zone Injection: The Integrity Risks in the September 2026 BIND Advisory Most DNS advisories are read as availability problems. CERT-In note CIVN-2026-0467 is not only that: it explicitly lists spoofing, cache poisoning, and unauthorized addition of data to a DNS zone among the possible outcomes of the 14 ISC BIND CVEs it covers. Vulnerability overview Published 21 September…
The September 2026 CERT-In advisory highlights 14 vulnerabilities in BIND versions 9.11.0 through 9.20.27, posing significant integrity risks. These flaws, attributed to use-after-free, numeric truncation errors, excessive resource consumption, and missing memory releases, enable attackers to manipulate the DNS system. Three vulnerabilities directly compromise the integrity boundary by allowing attackers to accept unverified or untrusted data.
Exploitation requires sending crafted DNS queries or responses, which, if successful, result in persistent cache poisoning for the record's time-to-live. The consequences are wrong answers, silently redirecting traffic, and compromising the legitimacy of DNS responses. While CERT-In doesn't claim active exploitation, affected products range from BIND 9.11.0 to 9.20.27 across multiple editions.
To mitigate risks, apply vendor updates and implement hardening measures such as DNSSEC validation, restricted recursion, TSIG for zone transfers, and disabling unnecessary dynamic updates. Monitoring for unauthorized changes is crucial as integrity failures often go unnoticed.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.