#VU124615 Missing release of memory after effective lifetime in ISC BIND - CVE-2026-3104
Published: March 25, 2026
ISC BIND
ISC
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper memory management in the DNSSEC proof preparation component when handling recursive queries for a specially crafted domain. A remote attacker can send a specially crafted domain query to cause unbounded memory consumption, leading to an out-of-memory condition and potential service termination during shutdown or reload.
Resolvers are affected; authoritative servers may be at risk if they perform recursive queries.