New BIND Releases Available - 9.18.29, 9.20.1, 9.21.0
Victoria Risk <[email protected]> Wed, 21 Aug 2024 08:38:11 -0400
| Newsgroups | gmane.network.dns.bind.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============5280197273608500903==
Content-Type: multipart/alternative;
boundary="Apple-Mail=_3476B373-7BD4-4DFB-BD68-625D59C4E80D"
--Apple-Mail=_3476B373-7BD4-4DFB-BD68-625D59C4E80D
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
BIND users-
Our August 2024 maintenance release of BIND 9.18, as well as the first =
maintenance release on the new 9.20 stable branch, and the brand new =
9.21 development branch, are available and can be downloaded from the =
ISC software download page, https://www.isc.org/download.
A summary of significant changes in the new releases can be found in =
their release notes:
- Current supported stable branches:
9.18.29 - =
https://downloads.isc.org/isc/bind9/9.18.29/doc/arm/html/notes.html =
<https://downloads.isc.org/isc/bind9/9.18.2/doc/arm/html/notes.html>
9.20.1 - =
https://downloads.isc.org/isc/bind9/9.20.1/doc/arm/html/notes.html
- New development branch:
9.20.1 - =
https://downloads.isc.org/isc/bind9/9.21.0/doc/arm/html/notes.html =
<https://downloads.isc.org/isc/bind9/9.2.1/doc/arm/html/notes.html>
If you haven=E2=80=99t seen it, check out the blog post from Ond=C5=99ej =
Sur=C3=BD on the 9.20 branch, including performance testing results =
(https://www.isc.org/blogs/2024-bind920/).
9.20 remains in the bind-dev package repositories for this release. We =
will roll the package repositories over, moving 9.20 to bind, and adding =
9.21 to bind-dev, sometime in the coming month.=20
---
Please Note:
To create an effective mitigation for CVE-2024-1737 we introduced two =
new configurable limits that prevent the loading (into zones or into =
cache) of DNS resource records (RRs) that exceed them. We therefore =
recommend reading this KB article,
https://kb.isc.org/docs/rrset-limits-in-zones, in case you need to =
change the defaults to suit your specific operational environment. (This =
change was introduced in 9.18.28 and has not changed with this release =
but it has surprised some users who didn=E2=80=99t notice this message =
previously.)
We recommend that users planning to upgrade from the EOL 9.16 branch =
read the following document first:
=
https://kb.isc.org/docs/changes-to-be-aware-of-when-moving-from-bind-916-t=
o-918
--Apple-Mail=_3476B373-7BD4-4DFB-BD68-625D59C4E80D
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
charset=utf-8
<html><head><meta http-equiv=3D"content-type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"overflow-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;"><div><span =
style=3D"text-wrap-mode: wrap; background-color: rgb(255, 255, =
255);">BIND users-</span></div><div><pre style=3D"text-wrap-mode: wrap; =
background-color: rgb(255, 255, 255);">
Our August 2024 maintenance release of BIND 9.18, as well as the first =
maintenance release on the new 9.20 stable branch, and the brand new =
9.21 development branch, are available and can be downloaded from the =
ISC software download page, <a =
href=3D"https://www.isc.org/download.">https://www.isc.org/download.</a>
A summary of significant changes in the new releases can be found in =
their release notes:
- Current supported stable branches:
9.18.29 - <a =
href=3D"https://downloads.isc.org/isc/bind9/9.18.2/doc/arm/html/notes.html=
">https://downloads.isc.org/isc/bind9/9.18.29/doc/arm/html/notes.html</a>
9.20.1 - <a =
href=3D"https://downloads.isc.org/isc/bind9/9.20.1/doc/arm/html/notes.html=
">https://downloads.isc.org/isc/bind9/9.20.1/doc/arm/html/notes.html</a></=
pre><pre style=3D"text-wrap-mode: wrap; background-color: rgb(255, 255, =
255);">- New development branch:</pre><pre style=3D"text-wrap-mode: =
wrap; background-color: rgb(255, 255, 255);"> 9.20.1 - <a =
href=3D"https://downloads.isc.org/isc/bind9/9.2.1/doc/arm/html/notes.html"=
style=3D"text-wrap-mode: =
wrap;">https://downloads.isc.org/isc/bind9/9.21.0/doc/arm/html/notes.html<=
/a><br>
If you haven=E2=80=99t seen it, check out the blog post from Ond=C5=99ej =
Sur=C3=BD on the 9.20 branch, including performance testing results (<a =
href=3D"https://www.isc.org/blogs/2024-bind920/">https://www.isc.org/blogs=
/2024-bind920/</a>).</pre><pre style=3D"text-wrap-mode: wrap; =
background-color: rgb(255, 255, 255);">9.20 remains in the bind-dev =
package repositories for this release. We will roll the package =
repositories over, moving 9.20 to bind, and adding 9.21 to bind-dev, =
sometime in the coming month. </pre><pre style=3D"text-wrap-mode: wrap; =
background-color: rgb(255, 255, 255);">
---
Please Note:
To create an effective mitigation for CVE-2024-1737 we introduced two =
new configurable limits that prevent the loading (into zones or into =
cache) of DNS resource records (RRs) that exceed them. We therefore =
recommend reading this KB article,
<a =
href=3D"https://kb.isc.org/docs/rrset-limits-in-zones,">https://kb.isc.org=
/docs/rrset-limits-in-zones,</a> in case you need to change the defaults =
to suit your specific operational environment. (This change was =
introduced in 9.18.28 and has not changed with this release but it has =
surprised some users who didn=E2=80=99t notice this message previously.)
We recommend that users planning to upgrade from the EOL 9.16 branch =
read the following document first:
<a =
href=3D"https://kb.isc.org/docs/changes-to-be-aware-of-when-moving-from-bi=
nd-916-to-918">https://kb.isc.org/docs/changes-to-be-aware-of-when-moving-=
from-bind-916-to-918</a>
</pre><br class=3D"Apple-interchange-newline"></div></body></html>=
--Apple-Mail=_3476B373-7BD4-4DFB-BD68-625D59C4E80D--
--===============5280197273608500903==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--
bind-announce mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-announce
--===============5280197273608500903==--