VYPR

rpm package

opensuse/bind&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/bind&distro=openSUSE%20Tumbleweed

Vulnerabilities (124)

  • CVE-2026-13321HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 throug

  • CVE-2026-13204HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50,

  • CVE-2026-12617HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds posit

  • CVE-2026-11721HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cac

  • CVE-2026-11622HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magni

  • CVE-2026-11605HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes th

  • CVE-2026-11331HigJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an

  • CVE-2026-10822MedJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the

  • CVE-2026-10723MedJul 22, 2026
    affected < 9.20.26-1.1fixed 9.20.26-1.1

    BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.

  • CVE-2026-5950MedMay 20, 2026
    affected < 9.20.23-1.1fixed 9.20.23-1.1

    An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versi

  • CVE-2026-5947HigMay 20, 2026
    affected < 9.20.23-1.1fixed 9.20.23-1.1

    Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would oc

  • CVE-2026-5946HigMay 20, 2026
    affected < 9.20.23-1.1fixed 9.20.23-1.1

    Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching t

  • CVE-2026-3593HigMay 20, 2026
    affected < 9.20.23-2.1fixed 9.20.23-2.1

    A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT af

  • CVE-2026-3592MedMay 20, 2026
    affected < 9.20.23-1.1fixed 9.20.23-1.1

    BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9

  • CVE-2026-3039HigMay 20, 2026
    affected < 9.20.23-1.1fixed 9.20.23-1.1

    BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments

  • CVE-2026-3591MedMar 25, 2026
    affected < 9.20.21-1.1fixed 9.20.21-1.1

    A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addr

  • CVE-2026-3119MedMar 25, 2026
    affected < 9.20.21-1.1fixed 9.20.21-1.1

    Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affect

  • CVE-2026-3104HigMar 25, 2026
    affected < 9.20.21-1.1fixed 9.20.21-1.1

    A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11

  • CVE-2026-1519HigMar 25, 2026
    affected < 9.20.21-1.1fixed 9.20.21-1.1

    If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see:

  • CVE-2025-13878HigJan 21, 2026
    affected < 9.20.18-1.1fixed 9.20.18-1.1

    Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.

Page 1 of 7