USN-8682-1: Bind vulnerabilities
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zhang discovered that Bind incorrectly handled self-pointed glue records. A remote attacker could possibly use this issue to use Bind in denial of service amplification attacks against other systems. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-3592) It was discovered that Bind incorrectly handled DNS messages whose class was not IN. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-5946)
CSIRTS triage
- What
- Bind contains multiple denial of service vulnerabilities: memory exhaustion during GSS-API TKEY negotiation, improper handling of self-pointed glue records enabling amplification attacks, and crashes on non-IN class DNS messages.
- Who is affected
- Bind DNS servers on Ubuntu 18.04 LTS, 20.04 LTS, and 22.04 LTS are vulnerable.
- Urgency
- High urgency; these vulnerabilities enable remote denial of service attacks and amplification attacks against third parties.
- Action
- Upgrade to the patched Bind version provided in Ubuntu security advisories.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Bind
Get an email when a new Bind advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8682-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-30391.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-35920.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-59461.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 78% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-3039 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3592 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-5946 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Ubuntu Security Notices
- unknownUSN-8683-1: libheif vulnerabilities2026-08-26
- unknownUSN-8681-1: OpenJDK 25 vulnerabilities2026-08-26
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25