Re: [BLFS Trac] #23776: bind9 bind 9.20.27
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23776: bind9 bind 9.20.27
-------------------------+--------------------------
Reporter: Bruce Dubbs | Owner: Bruce Dubbs
Type: enhancement | Status: assigned
Priority: normal | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+--------------------------
Comment (by Bruce Dubbs):
BIND 9.20.27
New Features
- Disclose active Negative Trust Anchors with Extended DNS Error 33.
- Add development guidance for AI coding agents under .agents/skills/
- Add more unit tests for isc_time API.
Feature Changes
- Batch qp transaction for RPZ updates.
- Pass the work callback result to the done callback.
Bug Fixes
- Dig +yaml producing invalid YAML when a lookup fails.
- Ensure NSEC authority does not cross zonecut boundary.
- Treat non canonical RPZ prefixes as any other failure.
- Properly prevent TSIG generation command line injection attacks.
- Dig with IDN output could leak memory on ISC_R_NOSPACE retry.
- Dnssec-signzone had a potential heap bounds overflow write.
- Restore SMF support on Solaris and illumos.
- Fix NULL pointer dereference in dnstap-read.
- Change catz coo locking.
- Treat an unusable NSEC3 chain as a verification failure.
- Unterminated OpenSSL private-key `Label:` field can be read past its
parser buffer.
- Negative caching stopped working with stale-answer-client-timeout 0.
- MacOS byte swapping macros already defined. ``5c1d3df49c0``
- Use memmove in isc_sockaddr_fromin/isc_sockaddr_fromin6.
- Fix compilation on GNU/Hurd.
- Restore arc4random() detection dropped in the v9.21.14 merge.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23776#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page