[BLFS Trac] #23332: bind9 bind 9.20.23
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23332: bind9 bind 9.20.23
-----------------------------+-----------------------
Reporter: Douglas R. Reno | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Keywords:
-----------------------------+-----------------------
New point version. Following Xi's recommendations, I'll file a separate
ticket for this one since it's another security update.
CVEs fixed include:
{{{
On 20 May 2026, Internet Systems Consortium disclosed six
vulnerabilities affecting our BIND 9 software:
- CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API
TKEY negotiation https://kb.isc.org/docs/cve-2026-3039
- CVE-2026-3592: Amplification vulnerabilities via self-pointed
glue records https://kb.isc.org/docs/cve-2026-3592
- CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-
over-HTTPS implementation https://kb.isc.org/docs/cve-2026-3593
- CVE-2026-5946: Invalid handling of CLASS != IN
https://kb.isc.org/docs/cve-2026-5946
- CVE-2026-5947: SIG(0) validation during query flood may lead to
undefined behavior https://kb.isc.org/docs/cve-2026-5947
- CVE-2026-5950: Unbounded resend loop in BIND 9 resolver
https://kb.isc.org/docs/cve-2026-5950
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23332>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page