📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology CRITICAL 58m Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 2h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h Global supply_chain Software Development and Technology CRITICAL 58m Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 2h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h Global supply_chain Software Development and Technology CRITICAL 58m Global data_breach Multiple Sectors HIGH 1h Global vulnerability Consumer Electronics / Mobile Devices CRITICAL 2h Global phishing Cybersecurity / Network Security CRITICAL 2h Global malware Critical Infrastructure / Government HIGH 2h Global supply_chain Cybersecurity / Software Supply Chain CRITICAL 3h Global general Multiple sectors MEDIUM 5h Global general Multiple sectors MEDIUM 5h Global malware Information Technology and Telecommunications HIGH 5h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 6h
Vulnerabilities

CVE-2026-3119

Medium
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction sign
CWE-617 — Weakness Type
Published: Mar 25, 2026  ·  Modified: Mar 28, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

🤖 AI Executive Summary

CVE-2026-3119 is a denial-of-service vulnerability in BIND 9 DNS servers that causes crashes when processing specially crafted TKEY records within validly signed TSIG queries. This affects BIND versions 9.20.0-9.20.20 and 9.21.0-9.21.19, requiring valid transaction signatures to exploit. While no public exploit exists and patches are unavailable, the vulnerability poses significant risk to Saudi DNS infrastructure, particularly for organizations running vulnerable BIND versions in production environments.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 12, 2026 22:01
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability directly impacts Saudi organizations operating BIND 9 DNS infrastructure, particularly: (1) ARAMCO and energy sector operators managing critical DNS services; (2) SAMA-regulated financial institutions and banks relying on BIND for DNS resolution; (3) Government agencies under NCA oversight operating DNS servers; (4) Telecom providers (STC, Mobily, Zain) managing nationwide DNS infrastructure; (5) Healthcare organizations under MOH jurisdiction. The DoS impact could disrupt critical services, though exploitation requires valid TSIG credentials, limiting attack surface to authenticated threat actors or compromised internal systems.
🏢 Affected Saudi Sectors
Energy (ARAMCO, oil/gas operators) Banking and Financial Services (SAMA-regulated) Government (NCA-regulated agencies) Telecommunications (STC, Mobily, Zain) Healthcare (MOH-regulated facilities) Critical Infrastructure Operators
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all BIND 9 installations and identify systems running versions 9.20.0-9.20.20 or 9.21.0-9.21.19
2. Review TSIG key configurations and restrict access to authorized DNS servers only
3. Implement network segmentation to limit DNS query sources
4. Enable comprehensive DNS query logging to detect anomalous TKEY record patterns

Compensating Controls (until patches available):
1. Implement rate limiting on TSIG-authenticated queries
2. Deploy DNS firewall rules to block TKEY records from untrusted sources
3. Monitor named process for unexpected crashes and implement automatic restart mechanisms
4. Restrict TSIG key distribution and rotate keys regularly
5. Consider temporary downgrade to BIND 9.18.x series (confirmed unaffected)

Detection Rules:
1. Monitor syslog for named crashes with TKEY-related error messages
2. Alert on TSIG-authenticated queries containing TKEY records
3. Track DNS query patterns for unusual TKEY record requests
4. Monitor named process CPU/memory anomalies preceding crashes
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع تثبيتات BIND 9 وتحديد الأنظمة التي تشغل الإصدارات 9.20.0-9.20.20 أو 9.21.0-9.21.19
2. مراجعة تكوينات مفاتيح TSIG وتقييد الوصول إلى خوادم DNS المصرح بها فقط
3. تنفيذ تقسيم الشبكة لتحديد مصادر استعلامات DNS
4. تفعيل تسجيل استعلامات DNS الشامل للكشف عن أنماط سجلات TKEY الشاذة

الضوابط البديلة (حتى توفر التصحيحات):
1. تنفيذ تحديد معدل على الاستعلامات المصرح بها بـ TSIG
2. نشر قواعد جدار حماية DNS لحجب سجلات TKEY من مصادر غير موثوقة
3. مراقبة عملية named للتوقفات غير المتوقعة وتنفيذ آليات إعادة التشغيل التلقائي
4. تقييد توزيع مفاتيح TSIG وتدوير المفاتيح بانتظام
5. النظر في الترقية المؤقتة إلى سلسلة BIND 9.18.x (مؤكد عدم تأثرها)

قواعد الكشف:
1. مراقبة syslog لتوقفات named برسائل خطأ متعلقة بـ TKEY
2. التنبيه على الاستعلامات المصرح بها بـ TSIG التي تحتوي على سجلات TKEY
3. تتبع أنماط استعلامات DNS للطلبات غير العادية لسجلات TKEY
4. مراقبة شذوذ CPU/الذاكرة في عملية named قبل التوقفات
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.2.1 - Change management procedures ECC 2024 A.12.3.1 - Segregation of development, test and production environments
🔵 SAMA CSF
SAMA CSF ID.BE-1 - Asset management and inventory SAMA CSF PR.IP-12 - Security patch management SAMA CSF DE.CM-1 - Detection and analysis of anomalies
🟡 ISO 27001:2022
ISO 27001:2022 A.12.3.1 - Change management ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.8.1.3 - Segregation of duties
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 11.2 - Vulnerability scanning
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-617
Exploit No
Patch ✗ No
Published 2026-03-25
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-617
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.