VDB

RHSA-2026%3A0420

RHSA-2026%3A0420 PUBLISHED CVSS 7.5 HIGH

A vulnerability was found in BIND 9 resolvers, where processing malformed DNSKEY records from a specially crafted zone can lead to resource exhaustion, primarily causing excessive CPU utilization. This issue enables a remote, unauthenticated attacker to degrade resolver performance and potentially cause a denial of service (DoS) for legitimate DNS clients.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhcos-x86_64-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20rhcos-x86_64-4.20.9.6.202601052146-0
Red Hatrhcos-aarch64-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20rhcos-aarch64-4.20.9.6.202601052146-0, rhcos-aarch64-4.20.9.6.202601052146-0
Red Hatrhcos-aarch64-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20rhcos-aarch64-4.20.9.6.202601052146-0
Red Hatrhcos-s390x-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20*
Red Hatrhcos-s390x-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20rhcos-s390x-4.20.9.6.202601052146-0, rhcos-s390x-4.20.9.6.202601052146-0
Red Hatrhcos-x86_64-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20rhcos-x86_64-4.20.9.6.202601052146-0, rhcos-x86_64-4.20.9.6.202601052146-0
Red Hatrhcos-ppc64le-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20rhcos-ppc64le-4.20.9.6.202601052146-0
Red Hatrhcos-ppc64le-4.20.9.6.202601052146-0 as a component of Red Hat OpenShift Container Platform 4.20*, *

Timeline

  • Jan 14, 2026 CVE Published
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 30, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›