gpp_maybe
Security update for bind
SUSE-SLE-Module-Server-Applications-15-SP7-2026-3426
This update for bind fixes the following issues: Upgrade to release 9.20.26. Security issues fixed: - CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). - CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected exit (bsc#1271983). - CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). - CVE-2026-11605: unnecessary validation of DNSSEC signed records (bsc#1271985). - CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). - CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). - CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME (bsc#1271988). - CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). - CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). Other updates and bugfixes: - Release 9.20.26: * Reclaim memory promptly when DNSSEC validations are canceled. * Removed Features: * Remove the secondary validator in query.c. * Remove ineffective TCP fallback after repeated UDP timeouts. * Feature Changes: * Fall back to TCP on receipt of a UDP response with a mismatched query ID. * Limit the number of glue records cached from a referral. * Fix a resolver stall on a CNAME response to a DS query. * Bug Fixes: * Fix a bug in DNS UPDATE processing with inline-signing enabled. * Properly detect private records before copying. * Tighten referral DS acceptance. * Don't synthesize negative responses with pending NSEC. * Check that an NSEC signer is at or above the name to be validated. * Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN. * Fix a deny-answer-aliases configuration bypass issue. * Reject external referrals from forwarders. * Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode. * Unvalidated opt-out NSEC3 could be accepted in insecurity proof. * Check wildcard signer and NOQNAME signer match. * Fix CNAME resolution failure caused by a cached SERVFAIL response. * Reject unsupported RSA DNSKEY shapes during DNSSEC validation. * Fix a bug in GeoIP2 string matching. * Fix DNS-over-HTTPS (DoH) quota configuration issue. * Truncated reply to a TSIG query no longer stalls the resolver. * Ignore updates removing DNSKEY RRset with class ANY. * Ignore 0-byte reads in the TCP read callback. * Only print per-zone glue stats when zone-statistics is set to full. * CDS/CDNSKEY records were not removed when re-configuring the server. * Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB. * Stop reusing outgoing TCP connections the peer has already closed. * Fix DNSSEC validation failures for names under an apex DNAME. * The resolver now removes other RRsets at the same name when caching a CNAME. * Fix nxdomain-redirect combined with dns64. * Fix DNS64 owner case after DNAME restart. * Clear REDIRECT flag when it isn't needed. * Disable output escaping in bind9.xsl. * Fix crash on badly configured secondary signer. * Fix a possible crash on concurrent TKEY DELETE for the same key. * Reject RRSIG records covering meta-types.
-
Release DateJul 30 2026
-
ReferencesBugzilla: 1271982, 1271983, 1271984, 1271985, 1271986, 1271987, 1271988, 1271989, 1271990
CVEs: CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.7 aarch64
-
Packages
Server Applications Module 15.7 ppc64le
-
Packages
Server Applications Module 15.7 s390x
-
Packages
Server Applications Module 15.7 x86_64
-
Packages