CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field 漏洞概述 CVE编号: CVE-2026-13321 标题: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field 文档版本: 2.0 发布日期: 2026年7月22日 受影响程序: BIND 9 受影响版本: - BIND: 9.11.0 -> 9.18.50, 9.20.0 -> 9.20.24, 9.21.0 -> 9.21.23 - BIND Supported Preview Edition: 9.11.3-S1 -> 9.18.50-S1, 9.20.9-S1 -> 9.20.24-S1 严重程度: High 可利用性: Remotely 描述: BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. 影响: An attacker controlling any DNSSEC-signed zone can craft NSEC records that span into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses (AD=1). CVSS Score: 8.6 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/H:A/N 工作区: No workarounds known. 活跃利用: We are not aware of any active exploits. 解决方案: Upgrade to the patched release most closely related to your current version of BIND 9: - 9.20.26 - 9.21.24 BIND Supported Preview Edition: A special feature preview branch of BIND provided to eligible ISC support customers. - 9.20.26-S1 致谢: ISC would like to thank Qifan Zhang of Palo Alto Networks for bringing this vulnerability to our attention. 文档修订历史: - 1.0 Early Notification, 15 July 2026 - 1.1 Revised the list of fixed versions, 20 July 2026 - 2.0 Public disclosure, 22 July 2026 相关文件: See our BIND 9 Security Vulnerability Matrix for a complete listing of security vulnerabilities and versions affected. 问题反馈: Questions regarding this advisory should be posted as confidential GitLab issues at: https://gitlab.isc.org/isc-projects/bind9/-/issues/new?issue[confidential]=true 注意: ISC patches only currently supported versions. When possible we indicate EOL versions affected. For current information on which versions are actively supported, please see https://www.isc.org/download/ ISC安全漏洞披露政策: Details of our current security advisory policy and practice can be found in the ISC Software Defect and Security Vulnerability Disclosure Policy at https://kb.isc.org/docs/aa-00861. 免责声明: Internet Systems Consortium (ISC) is providing this notice on an "AS IS" basis. No warranty or guarantee of any kind is expressed in this notice and none should be implied. ISC expressly excludes and disclaims any warranties regarding this notice or materials referred to in this notice, including, without limitation, any implied warranty of merchantability, fitness for a particular purpose, absence of hidden defects, or of non-infringement. Your use or reliance on this notice or materials referred to in this notice is at your own risk. ISC may change this notice at any time. A stand-alone copy or paraphrase of the text of this document that omits the document URL is an uncontrolled copy. Uncontrolled copies may lack important information, be out of date, or contain factual errors.