suse · CVE-2026-5950

Quick triage

Priority: medium Published: 2026-05-28 23:20:35 UTC Updated: 2026-05-28 23:20:35 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-5950 severity moderate: SUSE including 41 source package names (bind, bind-9.18.49-150600.3.24.1, …), 154 product×package rows across 21 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (21 product lines)): Known Not Affected 139, Fixed 9, First Fixed 6.

Description:

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

cvelogic Threat Intelligence