gpp_maybe
Security update for bind
SUSE-SLE-Module-Basesystem-15-SP7-2026-4285
This update for bind fixes the following issues: - CVE-2026-19033: Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (bsc#1280430). - CVE-2026-19662: qpcache NOQNAME proof use-after-free crashes recursive resolver (bsc#1280432). - CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (bsc#1280433). - CVE-2026-19667: Remote assertion failure via 16-bit length truncation in dns_ncache_add() (bsc#1280435). - CVE-2026-19668: Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (bsc#1280436). - CVE-2026-19941: checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (bsc#1280437). - CVE-2026-75029: Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (bsc#1280438). - CVE-2026-76163: named aborts on a TKEY query when the user configuration has no global options statement (bsc#1280439). - CVE-2026-77119: NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (bsc#1280440). - CVE-2026-77692: Unauthenticated remote crash of named via a single DoH SIG(0) request (bsc#1280441). - CVE-2026-78301: Out-of-zone database nodes can become authoritative zone cuts (bsc#1280442). - CVE-2026-80274: Validating resolver can abort while caching a mismatched NOQNAME proof (bsc#1280443). - CVE-2026-81563: SVCB AliasMode additional-data error leaks qpcache references (bsc#1280444). - CVE-2026-81736: Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (bsc#1280445). Changes for bind: Upgrade to release 9.20.29 New Features: * Disclose active Negative Trust Anchors with Extended DNS Error 33. Feature Changes: * Reject oversized and malformed DNSKEY records up front. * Speed up RPZ policy zone updates. Bug Fixes: * Prevent a crash when using both dns64 and filter-a. * Stop passing UDP client addresses to update-policy external helpers. * Missing required NSEC3 for delegation not detected. * Tighten EUI48 and EUI64 text parsing. * GeoIP ACL state could be stale or wrong after reload. * Honor DNSSEC policy key tag ranges. * Fix a double free in mdig when EDNS options are specified. * Fix a crash when an IXFR falls back to AXFR with updates still pending. * Fix DS requests to parental agents over TLS. * Fix the rndc-confgen -q (quiet) option. * Enforce query ACLs for redirect zones and searched DLZs. * Check asnum validity in GeoIP ACLs. * Fix a crash on remote-servers lists that reference themselves. * A record from outside a response policy zone could crash named. * Invalid key-store configuration could abort the DNSSEC tools. * NSEC signature set could bypass the secure-delegation check. * Fix a possible nsupdate issue when using GSS-TSIG. * Fix a crash with a single-element geoip sortlist. * Prevent out-of-bailiwick CNAMEs from evicting cached records. * Restore periodic cleanup of stale resolver address data. * Fix named-checkconf/named crash with malformed key name. * Prevent resolver crashes while processing DNS over TCP. * Ensure NSEC authority does not cross zonecut boundary. * Treat an unusable NSEC3 chain as a verification failure. * Treat non-canonical RPZ prefixes as any other failure. * Negative caching stopped working with stale-answer-client-timeout set to 0. * An unterminated OpenSSL private-key Label: field could be read past its parser buffer. * Restore SMF support on Solaris and illumos. * Fix compilation on GNU/Hurd. * dig +yaml was producing invalid YAML when a lookup failed. * Properly prevent TSIG generation command line injection attacks. * Fix a potential heap bounds overflow write in dnssec-signzone. * Fix crashes on invalid DNSTAP input in dnstap-read.
-
Release DateSep 22 2026
-
ReferencesBugzilla: 1280430, 1280432, 1280433, 1280435, 1280436, 1280437, 1280438, 1280439, 1280440, 1280441, 1280442, 1280443, 1280444, 1280445
CVEs: CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.7 aarch64
-
Packagesbind
Domain Name System (DNS) Server (named)bind-utils9.20.29-150700.3.32.2 lock src
Libraries for "bind" and utilities to query and test DNS9.20.29-150700.3.32.2 lock rpm
Basesystem Module 15.7 ppc64le
-
Packagesbind
Domain Name System (DNS) Server (named)bind-utils9.20.29-150700.3.32.2 lock src
Libraries for "bind" and utilities to query and test DNS9.20.29-150700.3.32.2 lock rpm
Basesystem Module 15.7 s390x
-
Packagesbind
Domain Name System (DNS) Server (named)bind-utils9.20.29-150700.3.32.2 lock src
Libraries for "bind" and utilities to query and test DNS9.20.29-150700.3.32.2 lock rpm
Basesystem Module 15.7 x86_64
-
Packagesbind
Domain Name System (DNS) Server (named)bind-utils9.20.29-150700.3.32.2 lock src
Libraries for "bind" and utilities to query and test DNS9.20.29-150700.3.32.2 lock rpm