Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE: 2021:1827-1 Critical: Bind Update Fixes Major Issues

opensuse
Calendar Grey July 10, 2021
Dist Opensuse Esm H88
openSUSE announces a critical bind update fixing important issues affecting stability and security of systems.
An update that fixes two vulnerabilities is now available

Description

This update for bind fixes the following issues:

- CVE-2021-25214: Fixed a broken inbound incremental zone update (IXFR)

which could have caused named to terminate unexpectedly (bsc#1185345).

- CVE-2021-25215: Fixed an assertion check which could have failed while

answering queries for DNAME records that required the DNAME to be

processed to resolve itself (bsc#1185345).

- Switched from /var/run to /run (bsc#1185073)

- Hardening: Compiled binary with PIE flags to make it position independent

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-1826=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

bind-9.16.6-22.7.1

bind-chrootenv-9.16.6-22.7.1

bind-debuginfo-9.16.6-22.7.1

bind-debugsource-9.16.6-22.7.1

bind-devel-9.16.6-22.7.1

bind-utils-9.16.6-22.7.1

bind-utils-debuginfo-9.16.6-22.7.1

libbind9-1600-9.16.6-22.7.1

libbind9-1600-debuginfo-9.16.6-22.7.1

libdns1605-9.16.6-22.7.1

libdns1605-debuginfo-9.16.6-22.7.1

libirs-devel-9.16.6-22.7.1

libirs1601-9.16.6-22.7.1

libirs1601-debuginfo-9.16.6-22.7.1

libisc1606-9.16.6-22.7.1

libisc1606-debuginfo-9.16.6-22.7.1

libisccc1600-9.16.6-22.7.1

libisccc1600-debuginfo-9.16.6-22.7.1

libisccfg1600-9.16.6-22.7.1

libisccfg1600-debuginfo-9.16.6-22.7.1

libns1604-9.16.6-22.7.1

libns1604-debuginfo-9.16.6-22.7.1

- openSUSE Leap 15.3 (noarch):

bind-doc-9.16.6-22.7.1

python3-bind-9.16.6-22.7.1

References

https://www.suse.com/security/cve/CVE-2021-25214.html

https://www.suse.com/security/cve/CVE-2021-25215.html

https://bugzilla.suse.com/1183453

https://bugzilla.suse.com/1185073

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1826-1
Rating: important
Affected Products: openSUSE Leap 15.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here