gpp_maybe
Security update for bind
SUSE-SLE-Module-Server-Applications-15-SP7-2026-2673
This update for bind fixes the following issues: Security issues: - CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). - CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592). - CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation (bsc#1265593). - CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594). - CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior (bsc#1265595). - CVE-2026-5950: Unbounded resend loop in BIND 9 resolver (bsc#1265596). Non security issue: - bind test failed with version 9.20.21 (bsc#1263494). - Upgrade to release 9.20.23
-
Release DateJul 2 2026
-
ReferencesBugzilla: 1263494, 1265591, 1265592, 1265594, 1265595, 1265596, 1265593
CVEs: CVE-2026-3039, CVE-2026-3592, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950, CVE-2026-3593 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.7 aarch64
-
Packages
Server Applications Module 15.7 ppc64le
-
Packages
Server Applications Module 15.7 x86_64
-
Packages
Server Applications Module 15.7 s390x
-
Packages