Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-3593 — ISC BIND 9 DNS-over-HTTPS HTTP/2 SETTINGS Use-After-Free

Summary

CVE-2026-3593: a use-after-free in BIND 9's DoH implementation—freed response buffers are read during HTTP/2 SETTINGS floods, crashing ASAN builds; fixed in 9.20.23 and 9.21.22.
CVE
CVE-2026-3593
Published
Collected

original ↗