ISC BIND に複数の脆弱性
予習
この記事のキーワード — タップで意味×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×2
複数
ふくすう
plural; multiple; several
N2×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out
N1×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は7月23日、ISC BINDにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。ISC(Internet Systems Consortium)が、ISC BINDの複数の脆弱性を公開している。
JVNでは、影響を受けるシステム、想定される影響、対策方法についてはISCのアドバイザリを参照するよう案内している。
CVE-2026-10723: Incorrect acceptance of NSEC3 records
CVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-11331: Potential wildcard CNAME RPZ policy bypass
CVE-2026-11605: Unnecessary validation of DNSSEC signed records
CVE-2026-11622: Potential memory usage beyond configured limits
CVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME
CVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present
CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
JVNでは、影響を受けるシステム、想定される影響、対策方法についてはISCのアドバイザリを参照するよう案内している。
CVE-2026-10723: Incorrect acceptance of NSEC3 records
CVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-11331: Potential wildcard CNAME RPZ policy bypass
CVE-2026-11605: Unnecessary validation of DNSSEC signed records
CVE-2026-11622: Potential memory usage beyond configured limits
CVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME
CVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present
CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
この記事の単語 (13)
×2
複数
ふくすう
plural; multiple; several
×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
及び
および
and; as well as
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
公開
こうかい
opening to the public; making available to the public; putting on display; exhibiting; showing (play, movie, etc.); holding (interview, etc.); open; public
×1
想定
そうてい
hypothesis; supposition; assumption
×1
対策
たいさく
measure; step; countermeasure; counterplan; countermove; strategy; preparation (e.g. for a test)
×1
方法
ほうほう
method; process; manner; way; means; technique
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out