Prepare for more frequent security updates for 2026

Victoria Risk <[email protected]> Mon, 11 May 2026 08:54:51 -0400
Newsgroups gmane.network.dns.bind.announce
Message-ID <[email protected]>
--===============4001309791578600993==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_B2A3CCCB-3A8F-4460-B421-CE43BE61187E"


--Apple-Mail=_B2A3CCCB-3A8F-4460-B421-CE43BE61187E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

BIND users,

Plan for more frequent BIND security updates, at least for the remainder =
of 2026.=20

Large language models (LLMs) are making it much easier to find software =
vulnerabilities in open source, lowering the bar for researchers and bad =
actors alike, and causing a temporary flood of vulnerability reports to =
us, and to many open source projects. We are currently triaging =
vulnerability reports, both from external reporters and our own LLM =
analysis, at a rate that exceeds 10X the historic levels. =
(https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/)

To manage the avalanche of reports, we are making a few changes to the =
BIND release process and vulnerability handling. We plan to re-evaluate =
these changes at the end of 2026.=20
- We are deferring the release of the next stable branch, BIND 9.22, =
until at least the end of 2026.
- We will end maintenance for 9.18 and 9.18-S as previously scheduled, =
at the end of June 2026.=20
I have updated the =E2=80=98roadmap=E2=80=99 document in our =
knowledgebase: https://kb.isc.org/docs/aa-00896 to reflect this change.=20=


Users who are currently running 9.18 or 9.18-S should make plans to =
update to 9.20 as soon as possible, because we will be focusing our =
efforts on fixing vulnerabilities in the 9.20 and 9.21 branches.=20

BIND users should plan for frequent security updates for the rest of the =
year. Although we have had an informal practice of limiting ourselves to =
a single security release per quarter, to relieve the pressure on =
operators to update frequently, the situation now demands some changes.
- For the foreseeable future, users should expect security fixes in =
every monthly BIND maintenance release.
- We will not be able to invest extra effort to determine exactly which =
minor release introduced an issue;  users should update to the latest =
maintenance version on their branch.
- We are now releasing reproduction tests at the time of vulnerability =
publication, because these are mostly already discoverable via LLM.=20

We may also begin issuing CVEs for more medium-severity issues, such as =
those that score in the CVSS 5 - 7 range. Our policy is to issue Early =
Vulnerability Notices (EVNs) only for CVSS scores of 7 or higher, which =
is not changing. We may not always backport fixes for medium-severity =
CVEs, depending on the specific case. We welcome feedback on whether =
issuing CVEs for lower-severity problems would conflict with any of your =
internal policies.

These things, however, will not change:

- We will continue to aggressively pursue and fix reported =
vulnerabilities in BIND 9. We develop these fixes in a private =
repository and merge them into the public repository right before =
release, to protect our users from early disclosure.=20
- We will continue to assign CVE numbers for all issues that score over =
7.0 on the CVSS scale.=20
- We will continue to maintain BIND 9.20 and 9.20-S, and to develop =
9.21. We have not paused new feature development, although we are =
prioritizing addressing the vulnerabilities.=20

We plan to reevaluate this situation in Q4 2026, and we hope that we =
will be able to return to our normal release cadence in Q1 2027.=20

We appreciate your understanding and flexibility as we work to keep BIND =
safe and reliable for our users.

Regards,

Vicky Risk



--Apple-Mail=_B2A3CCCB-3A8F-4460-B421-CE43BE61187E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" =
content=3D"text/html; charset=3Dutf-8"></head><body =
style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; =
line-break: after-white-space;">BIND users,<br><br>Plan for more =
frequent BIND security updates, at least for the remainder of =
2026.&nbsp;<div><br></div><div>Large language models (LLMs) are making =
it much easier to find software vulnerabilities in open source, lowering =
the bar for researchers and bad actors alike, and causing a temporary =
flood of vulnerability reports to us, and to many open source projects. =
We are currently triaging vulnerability reports, both from external =
reporters and our own LLM analysis, at a rate that exceeds 10X the =
historic levels. (<a =
href=3D"https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability=
/">https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/</a>=
)<br><br>To manage the avalanche of reports, we are making a few changes =
to the BIND release process and vulnerability handling. We plan to =
re-evaluate these changes at the end of 2026.&nbsp;<br>- We are =
deferring the release of the next stable branch, BIND 9.22, until at =
least the end of 2026.<br>- We will end maintenance for 9.18 and 9.18-S =
as previously scheduled, at the end of June 2026.&nbsp;<div>I have =
updated the =E2=80=98roadmap=E2=80=99 document in our =
knowledgebase:&nbsp;<a =
href=3D"https://kb.isc.org/docs/aa-00896">https://kb.isc.org/docs/aa-00896=
</a>&nbsp;to reflect this change.&nbsp;<br><br><b>Users who are =
currently running 9.18 or 9.18-S should make plans to update to 9.20 as =
soon as possible, because we will be focusing our efforts on fixing =
vulnerabilities in the 9.20 and 9.21 branches.&nbsp;</b><br><br>BIND =
users should plan for frequent security updates for the rest of the =
year. Although we have had an informal practice of limiting ourselves to =
a single security release per quarter, to relieve the pressure on =
operators to update frequently, the situation now demands some =
changes.<br>- For the foreseeable future, users should expect security =
fixes in every monthly BIND maintenance release.<br>- We will not be =
able to invest extra effort to determine exactly which minor release =
introduced an issue; &nbsp;users should update to the latest maintenance =
version on their branch.<br>- We are now releasing reproduction tests at =
the time of vulnerability publication, because these are mostly already =
discoverable via LLM.&nbsp;<br><br>We may also begin issuing CVEs for =
more medium-severity issues, such as those that score in the CVSS 5 - 7 =
range. Our policy is to issue Early Vulnerability Notices (EVNs) only =
for CVSS scores of 7 or higher, which is not changing. We may not always =
backport fixes for medium-severity CVEs, depending on the specific case. =
We welcome feedback on whether issuing CVEs for lower-severity problems =
would conflict with any of your internal policies.<br><br>These things, =
however, will not change:<br><br>- We will continue to aggressively =
pursue and fix reported vulnerabilities in BIND 9. We develop these =
fixes in a private repository and merge them into the public repository =
right before release, to protect our users from early =
disclosure.&nbsp;<br>- We will continue to assign CVE numbers for all =
issues that score over 7.0 on the CVSS scale.&nbsp;<br>- We will =
continue to maintain BIND 9.20 and 9.20-S, and to develop 9.21. We have =
not paused new feature development, although we are prioritizing =
addressing the vulnerabilities.&nbsp;<br><br>We plan to reevaluate this =
situation in Q4 2026, and we hope that we will be able to return to our =
normal release cadence in Q1 2027.&nbsp;<br><br>We appreciate your =
understanding and flexibility as we work to keep BIND safe and reliable =
for our users.<br><br>Regards,<br><br>Vicky =
Risk<br><div><br></div><div><br></div></div></div></body></html>=

--Apple-Mail=_B2A3CCCB-3A8F-4460-B421-CE43BE61187E--

--===============4001309791578600993==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
bind-announce mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-announce

--===============4001309791578600993==--