Medium [CVE-2026-10822] Key Record using PRIVATEDNS algorithm may lead to exit
This medium-severity Red Hat Linux advisory covers CVE-2026-10822 affecting Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.).
That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing.
Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-617.
Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:54071.
Affected products named by the advisory: Red Hat package: bind9.16; Red Hat package: bind9.18; Red Hat package: dhcp.
- 9.18.0
- 9.18.50
- 9.20.0
- 9.20.24
- 9.21.0
- 9.21.23
- 9.18.11
- 9.20.9
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
- bind-main-9.20.26-0.1.hum1
- RHSA-2026:54071
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Mitigation checklist
- Upgrade to the patched release most closely related to your current version of BIND 9: - 9.20.26 - 9.21.24 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. - 9.20.26-S1
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.