IBM Support

Security Bulletin: Multiple vulnerabilities impact AIX due to ISC BIND

Security Bulletin


Summary

Vulnerabilities in ISC BIND could cause: Allowing forged authenticated NXDOMAIN responses (CVE-2026-10723), Denial of service (CVE-2026-10822, CVE-2026-11331, CVE-2026-11622, CVE-2026-12617, CVE-2026-13204), DNS cache poisoning (CVE-2026-11721, CVE-2026-13321). AIX uses ISC BIND as part of its DNS functions.

Vulnerability Details

CVEID:   CVE-2026-10723
DESCRIPTION:   BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-347: Improper Verification of Cryptographic Signature
CVSS Source:   security-officer@isc.org
CVSS Base score:   6.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N)

CVEID:   CVE-2026-10822
DESCRIPTION:   If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-617: Reachable Assertion
CVSS Source:   security-officer@isc.org
CVSS Base score:   6.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

CVEID:   CVE-2026-11622
DESCRIPTION:   A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source:   security-officer@isc.org
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:   CVE-2026-11721
DESCRIPTION:   It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-1284: Improper Validation of Specified Quantity in Input
CVSS Source:   security-officer@isc.org
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

CVEID:   CVE-2026-13204
DESCRIPTION:   If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-617: Reachable Assertion
CVSS Source:   security-officer@isc.org
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:   CVE-2026-13321
DESCRIPTION:   The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-346: Origin Validation Error
CVSS Source:   security-officer@isc.org
CVSS Base score:   8.6
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)

CVEID:   CVE-2026-11331
DESCRIPTION:   An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-790: Improper Filtering of Special Elements
CVSS Source:   security-officer@isc.org
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:   CVE-2026-12617
DESCRIPTION:   The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CWE:   CWE-617: Reachable Assertion
CVSS Source:   security-officer@isc.org
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s)Version(s)
AIX7.2
AIX7.3
VIOS4.1

 

 The vulnerabilities are being addressed for the following filesets:

 key_fileset = aix

FilesetLower LevelUpper Level KEY
bind.rte 7.1.916.07.1.916.4800key_w_fs
bind.rte 7.2.916.07.2.916.4801key_w_fs
bind.rte 7.2.918.07.2.918.4900key_w_fs
bind.rte 7.3.916.07.3.916.4800key_w_fs
bind.rte 7.3.918.07.3.918.4900key_w_fs

 

Note:

A. Latest level of BIND fileset is available from the web download site:

https://www.ibm.com/resources/mrs/assets?source=aixbp

 

To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in AIX user's guide.

Example:  lslpp -L | grep -i bind.rte

Remediation/Fixes

REMEDIATION:

A. FIXES

IBM strongly recommends addressing the vulnerability now.

The AIX and VIOS fixes can be downloaded via https from:

https://aix.software.ibm.com/aix/efixes/security/bind_fix31.tar

 

The fileset update has a dependency on OpenSSL 3.0. OpenSSL 3.0 may be downloaded from:

https://www.ibm.com/resources/mrs/assets?source=aixbp

 

The link above is to a tar file containing this signed advisory, install packages, and OpenSSL signatures for each package. The fixes below include prerequisite checking. This will enforce the correct mapping between the fixes and AIX Technology Levels.

 

To extract the fixes from the tar file:

tar xvf bind_fix31.tar

 

For AIX 7.2 (requires OpenSSL 3.0):

tar xvf bind_fix31/72bind920.tar

 

For AIX 7.3 and VIOS 4.1:

tar xvf bind_fix31/73bind920.tar

 

IMPORTANT: If possible, it is recommended that a mksysb backup of the system be created. Verify it is both bootable and readable before proceeding.

 

To preview the fix installation:

installp -apYd . bind

 

To install the fix package:

installp -aXYd . bind

 

Verify you have retrieved the fixes intact:

The checksums below were generated using the following command

"openssl dgst -sha256 [file]" 

openssl dgst -sha256 filenameKEY
020823947e7972c028dc946d91c5ec1db29f359b14168a30685b2b000cc2e4e172bind.rtekey_w_csum
274e3da930593a7c3c209b65eb31fb35092f29c2c29e6db6d84fc5f1d58170db73bind.rtekey_w_csum

 

openssl dgst -sha512 filenameKEY
cfdc8b558a5da6a7d1e6c9fa010e41e132f4bf54cdfbc6590dcacd84e56a87650aa4b99dde40fba154737ef8fe7940383675274b0cdf7cdab254c4aba1b476cf72bind.rtekey_4K_w_csum
de4630037befa218258c36fee9cad4245d5ed0a2d7cf8a17d7e5b8bbfacb1e45daae808e3dc9cdd41e358e2106819163aa5c2ccbf876f330da2c451baa847c0573bind.rtekey_4K_w_csum

 

These sums should match exactly. The OpenSSL signatures in the tar file and on this advisory can also be used to verify the integrity of the fixes.  If the sums or signatures cannot be confirmed, contact IBM Support at http://ibm.com/support/ and describe the discrepancy.

openssl dgst -sha256 -verify [pubkey_file] -signature [advisory_file].sig [advisory_file]

openssl dgst -sha256 -verify [pubkey_file] -signature [ifix_file].sig [ifix_file]

 

Published advisory OpenSSL signature file location:

https://aix.software.ibm.com/aix/efixes/security/bind_advisory31.asc.sig

 

B. FIX AND INTERIM FIX INSTALLATION

If possible, it is recommended that a mksysb backup of the system be created. Verify it is both bootable and readable before proceeding.

 

To preview a fix installation:

installp -a -d fix_name -p all  # where fix_name is the name of the

                                            # fix package being previewed.

To install a fix package:

installp -a -d fix_name -X all  # where fix_name is the name of the

                                            # fix package being installed.

 

Interim fixes have had limited functional and regression testing but not the full regression testing that takes place for Service Packs; however, IBM does fully support them.

 

Interim fix management documentation can be found at:

https://www.ibm.com/support/pages/managing-interim-fixes-aix

 

To preview an interim fix installation:

emgr -e ipkg_name -p         # where ipkg_name is the name of the

                                         # interim fix package being previewed.

 

To install an interim fix package:

emgr -e ipkg_name -X         # where ipkg_name is the name of the

                                         # interim fix package being installed.

 

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

16 Sep 2026: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY. In addition to other efforts to address potential vulnerabilities, IBM periodically updates the record of components contained in our product offerings. As part of that effort, if IBM identifies previously unidentified packages in a product/service inventory, we address relevant vulnerabilities regardless of CVE date. Inclusion of an older CVEID does not demonstrate that the referenced product has been used by IBM since that date, nor that IBM was aware of a vulnerability as of that date. We are making clients aware of relevant vulnerabilities as we become aware of them. "Affected Products and Versions" referenced in IBM Security Bulletins are intended to be only products and versions that are supported by IBM and have not passed their end-of-support or warranty date. Thus, failure to reference unsupported or extended-support products and versions in this Security Bulletin does not constitute a determination by IBM that they are unaffected by the vulnerability. Reference to one or more unsupported versions in this Security Bulletin shall not create an obligation for IBM to provide fixes for any unsupported or extended-support products or versions.

Document Location

Worldwide

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG10","label":"AIX"},"Component":"","Platform":[{"code":"PF002","label":"AIX"}],"Version":"7.2, 7.3","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSPHKW","label":"PowerVM Virtual I\/O Server"},"Component":"","Platform":[{"code":"PF002","label":"AIX"}],"Version":"4.1","Edition":"","Line of Business":{"code":"LOB57","label":"Power"}}]

Document Information

Modified date:
16 September 2026

Initial Publish date:
16 September 2026

UID

ibm17287477