CVE-2019-6476: ISC BIND

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.

Affected products

  • ISC BIND: from 9.14.0, up to and including 9.14.6; from 9.15.0, up to and including 9.15.4

Published 2019-10-17. Last modified 2026-06-17.