Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 43 bind9-next Critical DNS Fix CVE-2026-1519 DoS 2026-a6efefa854

fedora
Calendar Grey April 3, 2026
Dist Fedora Esm H88
Update for Fedora 43 bind9-next 9.21.20 addresses critical DNS issues and enhances security measures effectively.
Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations

Summary

BIND (Berkeley Internet Name Domain) is an implementation of the DNS

(Domain Name System) protocols. BIND includes a DNS server (named),

which resolves host names to IP addresses; a resolver library

(routines for applications to use when interfacing with DNS); and

tools for verifying that the DNS server is operating properly.

Update Information:

Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. (CVE-2026-1519) Fix memory leaks in code preparing DNSSEC proofs of non-existence. (CVE-2026-3104) Prevent a crash in code processing queries containing a TKEY record. (CVE-2026-3119) Fix a stack use-after-return flaw in SIG(0) handling code. (CVE-2026-3591) New Features: Provide response round-trip time (RTT) counters via statistics channel. Introduce max-delegation-servers configuration option. Bug Fixes: Fix parsing key inactivation time in KASP code. Fix the handling of key statements defined inside views. Update to 9.21.19 Security Fixes: Fix a use-after-free error in dns_client_resolve() triggered by a DNAME response. Fix a NULL pointer dereference in qp-trie cache code. Immediately remove purged ADB names and entries from the SIEVE list. Feature Changes: Record query time for all dnstap responses. Optimize TCP source port selection on Linux. and m...

Change Log

* Wed Mar 25 2026 Petr Men\u0161k - 32:9.21.20-1 - Update to 9.21.20 (rhbz#2440560)

References


[ 1 ] Bug #2440560 - bind9-next-9.21.20 is available https://bugzilla.redhat.com/show_bug.cgi?id=2440560 [ 2 ] Bug #2451573 - CVE-2026-3591 bind9-next: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2451573

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a6efefa854' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: bind9-next
Product: Fedora 43
Version: 9.21.20
Release: 1.fc43
Summary: The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here