BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

**Critical BIND 9 Update Released, Fixing 14 Flaws and a Potentially Catastrophic DNS-over-HTTPS Vulnerability**

A massive update has been rolled out for the BIND 9 domain name system (DNS) software, patching no less than 14 critical vulnerabilities in one fell swoop. Among these is an unauthenticated crash bug that can be triggered over the more secure DNS-over-HTTPS (DoH) protocol – a scenario that’s particularly unsettling given the growing adoption of DoH as a means to bolster internet security.

The BIND 9 software, widely used by network administrators around the world, is responsible for translating human-readable domain names into IP addresses that computers can understand. When it comes to vulnerabilities in such critical infrastructure, even one flaw can have far-reaching consequences – particularly if exploited maliciously. That’s why this update should be at the top of every administrator’s priority list.

Among the 14 patched flaws are several high-severity issues, including the aforementioned DoH vulnerability and a remote code execution (RCE) bug that can lead to full system compromise. Others include denial-of-service (DoS) vulnerabilities and privilege escalation bugs – all of which could potentially be exploited by sophisticated attackers. The update also addresses a few lesser-known issues, such as resource exhaustion attacks on BIND servers.

The good news is that this update doesn’t require administrators to completely reconfigure their DNS infrastructure from scratch. Instead, it allows them to seamlessly integrate the patches into existing systems without disrupting service. According to the developers’ release notes, users can apply the fixes using a variety of methods, including command-line instructions and automated tools.

The DoH vulnerability in question is particularly worrying because it involves an unauthenticated crash bug – a situation where even an anonymous attacker could potentially trigger a crash on affected BIND 9 servers. The DoH protocol was designed to improve DNS security by encrypting data between clients and recursive resolvers, but this flaw shows that not all is well when it comes to securing the underlying infrastructure.

Given the critical nature of these patches and their potential impact on network security, administrators are urged to apply the fixes as soon as possible. With a growing number of organizations embracing DoH as a means to secure DNS queries, it’s essential that users remain vigilant in addressing vulnerabilities such as this one.


Source: The Hacker News — 2026-09-17