1.
aretiq.ai | research | | original ↗ | #vulnerability-research | #denial-of-service | #use-after-free | #bind9
CVE-2026-3593: a use-after-free in BIND 9's DoH implementation—freed response buffers are read during HTTP/2 SETTINGS floods, crashing ASAN builds; fixed in 9.20.23 and 9.21.22.
Skip to content