rpm package
opensuse/bind&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/bind&distro=openSUSE%20Tumbleweed
Vulnerabilities (138)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-80274 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects B | |
| CVE-2026-77119 | Med | 5.9 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9 | |
| CVE-2026-76163 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 throug | |
| CVE-2026-75029 | Med | 5.3 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative | |
| CVE-2026-19668 | Med | 5.3 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions | |
| CVE-2026-19666 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through | |
| CVE-2026-19033 | Med | 6.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorize | |
| CVE-2026-81736 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.2 | |
| CVE-2026-81563 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive | |
| CVE-2026-78301 | Med | 5.8 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status a | |
| CVE-2026-77692 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9- | |
| CVE-2026-19941 | Med | 5.9 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 throu | |
| CVE-2026-19667 | Hig | 7.5 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9 | |
| CVE-2026-19662 | Med | 5.9 | < 9.20.29-1.1 | 9.20.29-1.1 | Sep 16, 2026 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of | |
| CVE-2026-13321 | Hig | 8.6 | < 9.20.26-1.1 | 9.20.26-1.1 | Jul 22, 2026 | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 throug | |
| CVE-2026-13204 | Hig | 7.5 | < 9.20.26-1.1 | 9.20.26-1.1 | Jul 22, 2026 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, | |
| CVE-2026-12617 | Hig | 7.5 | < 9.20.26-1.1 | 9.20.26-1.1 | Jul 22, 2026 | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds posit | |
| CVE-2026-11721 | Hig | 7.5 | < 9.20.26-1.1 | 9.20.26-1.1 | Jul 22, 2026 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cac | |
| CVE-2026-11622 | Hig | 7.5 | < 9.20.26-1.1 | 9.20.26-1.1 | Jul 22, 2026 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magni | |
| CVE-2026-11605 | Hig | 7.5 | < 9.20.26-1.1 | 9.20.26-1.1 | Jul 22, 2026 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes th |
- affected < 9.20.29-1.1fixed 9.20.29-1.1
If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects B
- affected < 9.20.29-1.1fixed 9.20.29-1.1
A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9
- affected < 9.20.29-1.1fixed 9.20.29-1.1
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 throug
- affected < 9.20.29-1.1fixed 9.20.29-1.1
In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative
- affected < 9.20.29-1.1fixed 9.20.29-1.1
A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions
- affected < 9.20.29-1.1fixed 9.20.29-1.1
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through
- affected < 9.20.29-1.1fixed 9.20.29-1.1
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorize
- affected < 9.20.29-1.1fixed 9.20.29-1.1
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.2
- affected < 9.20.29-1.1fixed 9.20.29-1.1
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive
- affected < 9.20.29-1.1fixed 9.20.29-1.1
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status a
- affected < 9.20.29-1.1fixed 9.20.29-1.1
An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-
- affected < 9.20.29-1.1fixed 9.20.29-1.1
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 throu
- affected < 9.20.29-1.1fixed 9.20.29-1.1
If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9
- affected < 9.20.29-1.1fixed 9.20.29-1.1
An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of
- affected < 9.20.26-1.1fixed 9.20.26-1.1
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 throug
- affected < 9.20.26-1.1fixed 9.20.26-1.1
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50,
- affected < 9.20.26-1.1fixed 9.20.26-1.1
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds posit
- affected < 9.20.26-1.1fixed 9.20.26-1.1
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cac
- affected < 9.20.26-1.1fixed 9.20.26-1.1
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magni
- affected < 9.20.26-1.1fixed 9.20.26-1.1
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes th
Page 1 of 7