BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols. BIND includes a DNS server (named),
which resolves host names to IP addresses; a resolver library
(routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating properly.
Update Information:
Update to 9.21.22 (rhbz#2480122) Security Fixes: Limit resolver server list size. (CVE-2026-3592) Fix GSS-API resource leak. (CVE-2026-3039) Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946) Avoid unbounded recursion loop. (CVE-2026-5950) Fix crash in resolver when SIG(0)-signed responses are received under load. (CVE-2026-5947) Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. (CVE-2026-3593) Fix outgoing zone transfers' quota issue. Feature Changes: Fix CPU spikes and slow queries when cache approaches memory limit. Implement RFC 3645 Section 4.1.1 key expiry check in TKEY. Reduce memory footprint by actively returning unused memory to the OS. multiple bugfixes. Source: https://downloads.isc.org/isc/bind9/9.21.22/doc/arm/html/notes.html#notes-for- bind-9-21-22
* Fri Jun 5 2026 Petr Menšík
[ 1 ] Bug #2480122 - bind9-next-9.21.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=2480122
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec095a4675' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.