Re: [BLFS Trac] #23637: bind9 bind 9.20.26
BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]> Thu, 23 Jul 2026 17:17:54 -0000
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23637: bind9 bind 9.20.26
-------------------------+------------------------
Reporter: Bruce Dubbs | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: high | Resolution:
Keywords: |
-------------------------+------------------------
Changes (by Joe Locash):
* priority: normal => high
* severity: normal => high
Comment:
{{{
Message-ID: <[email protected]>
Date: Wed, 22 Jul 2026 16:01:19 +0200
From: Michał Kępień <[email protected]>
To: [email protected]
Cc: [email protected]
Subject: ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723,
CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622,
CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
On 22 July 2026, Internet Systems Consortium disclosed nine
vulnerabilities affecting our BIND 9 software:
- CVE-2026-10723: Incorrect acceptance of NSEC3 records
https://kb.isc.org/docs/cve-2026-10723
- CVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to
unexpected exit https://kb.isc.org/docs/cve-2026-10822
- CVE-2026-11331: Potential wildcard CNAME RPZ policy bypass
https://kb.isc.org/docs/cve-2026-11331
- CVE-2026-11605: Unnecessary validation of DNSSEC signed records
https://kb.isc.org/docs/cve-2026-11605
- CVE-2026-11622: Potential memory usage beyond configured limits
https://kb.isc.org/docs/cve-2026-11622
- CVE-2026-11721: Cache poisoning possible with label count
discrepancy, RRSIG, and wildcards https://kb.isc.org/docs/cve-2026-11721
- CVE-2026-12617: Record ordering based unexpected exit with CNAME
or DNAME https://kb.isc.org/docs/cve-2026-12617
- CVE-2026-13204: Unexpected exit in certain situations with NSEC
and NSEC3 both present https://kb.isc.org/docs/cve-2026-13204
- CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next
Field https://kb.isc.org/docs/cve-2026-13321
New versions of BIND 9 are available:
- https://downloads.isc.org/isc/bind9/9.20.26/
- https://downloads.isc.org/isc/bind9/9.21.24/
For more information and other release formats, consult the ISC software
download page: https://www.isc.org/download/
With the public announcement of these vulnerabilities, the embargo period
is ended and any updated software packages that have been prepared may be
released.
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23637#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page