This update for bind fixes the following issues
Upgrade to release 9.20.23:
- CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591).
- CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592).
- CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation (bsc#1265593).
- CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594).
- CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior (bsc#1265595).
- CVE-2026-5950: Unbounded resend loop in BIND 9 resolver (bsc#1265596).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-988=1
- openSUSE Leap 16.0:
bind-9.20.23-160000.1.1
bind-doc-9.20.23-160000.1.1
bind-modules-bdbhpt-9.20.23-160000.1.1
bind-modules-generic-9.20.23-160000.1.1
bind-modules-ldap-9.20.23-160000.1.1
bind-modules-mysql-9.20.23-160000.1.1
bind-modules-perl-9.20.23-160000.1.1
bind-modules-sqlite3-9.20.23-160000.1.1
bind-utils-9.20.23-160000.1.1
* bsc#1265591
* bsc#1265592
* bsc#1265593
* bsc#1265594
* bsc#1265595
* bsc#1265596
References:
* https://www.suse.com/security/cve/CVE-2026-3039.html
* https://www.suse.com/security/cve/CVE-2026-3592.html
* https://www.suse.com/security/cve/CVE-2026-3593.html
* https://www.suse.com/security/cve/CVE-2026-5946.html
* https://www.suse.com/security/cve/CVE-2026-5947.html
* https://www.suse.com/security/cve/CVE-2026-5950.html
Get the latest Linux and open source security news straight to your inbox.