Bug 2504370 (CVE-2026-12617)

Summary: CVE-2026-12617 bind: bind9: Record ordering based unexpected exit with CNAME or DNAME
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, pemensik, ppalepu, ppostler, prdhamdh, rhel-process-autobot, security-response-team, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers, yozone
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, named may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-07-22   

Description OSIDB Bzimport 2026-07-21 20:35:01 UTC
Specific CNAME/DNAME + A record query ordering with delayed
authoritative responses can cause an assertion exit. Requires
specific timing of authoritative server responses.

Comment 2 Petr Menšík 2026-08-04 08:55:56 UTC
It seems that this CVE does not affect our older version. Because at least described way to trigger requires change we do not yet have in our released versions. That was added in version 9.18.36, 3 minor versions before our latest 9.18 version. Fedor has commented more details in issue RHEL-213450.