Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. (CVE-2026-1519) Fix memory leaks in code preparing DNSSEC proofs of non-existence.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a6efefa854 2026-04-03 00:50:26.407464+00:00 -------------------------------------------------------------------------------- Name : bind9-next Product : Fedora 43 Version : 9.21.20 Release : 1.fc43 URL : https://www.isc.org/downloads/bind/ Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Update to 9.21.20 (rhbz#2440560) Security Fixes: Fix unbounded NSEC3 iterations when validating referrals to unsigned delegations. (CVE-2026-1519) Fix memory leaks in code preparing DNSSEC proofs of non-existence. (CVE-2026-3104) Prevent a crash in code processing queries containing a TKEY record. (CVE-2026-3119) Fix a stack use-after-return flaw in SIG(0) handling code. (CVE-2026-3591) New Features: Provide response round-trip time (RTT) counters via statistics channel. Introduce max-delegation-servers configuration option. Bug Fixes: Fix parsing key inactivation time in KASP code. Fix the handling of key statements defined inside views. Update to 9.21.19 Security Fixes: Fix a use-after-free error in dns_client_resolve() triggered by a DNAME response. Fix a NULL pointer dereference in qp-trie cache code. Immediately remove purged ADB names and entries from the SIEVE list. Feature Changes: Recordquery time for all dnstap responses. Optimize TCP source port selection on Linux. and multiple bug fixes. Update to 9.21.18 Feature Changes: Enable minimal ANY answers by default. Lowercase the NSEC Next Domain Name field. Update requirements for system test suite. Bug Fixes: Make catalog zone names and member zones' entry names case-insensitive. [GL #5693] Fix implementation of BRID and HHIT record types. [GL #5710] Fix implementation of DSYNC record type. [GL #5711] Fix response policy and catalog zones to work with $INCLUDE directive. Source: https://downloads.isc.org/isc/bind9/9.21.20/doc/arm/html/notes.html#notes-for- bind-9-21-20 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Petr Men\u0161k - 32:9.21.20-1 - Update to 9.21.20 (rhbz#2440560) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2440560 - bind9-next-9.21.20 is available https://bugzilla.redhat.com/show_bug.cgi?id=2440560 [ 2 ] Bug #2451573 - CVE-2026-3591 bind9-next: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2451573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a6efefa854' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 bind9-next 9.21.20 addresses critical DNS issues and enhances security measures effectively.. BIND fixes,node security update,Fedora advisory,memory leak fix,DNS security. .Severity: Critical. LinuxSecurity.com Team
New bind packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bind (SSA:2024-044-01) New bind packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/bind-9.16.48-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and security issues: Specific DNS answers could cause a denial-of-service condition due to DNS validation taking a long time. Query patterns that continuously triggered cache database maintenance could exhaust all available memory on the host running named. Restore DNS64 state when handling a serve-stale timeout. Specific queries could trigger an assertion check with nxdomain-redirect enabled. Speed up parsing of DNS messages with many different names. For more information, see: https://kb.isc.org/docs/cve-2023-50387 https://www.cve.org/CVERecord?id=CVE-2023-50387 https://kb.isc.org/docs/cve-2023-6516 https://www.cve.org/CVERecord?id=CVE-2023-6516 https://kb.isc.org/docs/cve-2023-5679 https://www.cve.org/CVERecord?id=CVE-2023-5679 https://kb.isc.org/docs/cve-2023-5517 https://www.cve.org/CVERecord?id=CVE-2023-5517 https://kb.isc.org/docs/cve-2023-4408 https://www.cve.org/CVERecord?id=CVE-2023-4408 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 688d05942acae07ca040a07057f107af bind-9.16.48-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 72ec1aa452c6b37046e74b90797be3e8 bind-9.16.48-x86_64-1_slack15.0.txz Slackware -current package: 8e3c11dba6a01af76aa89531c2e2d62a n/bind-9.18.24-i586-1.txz Slackware x86_64 -current package: 8a9d10f4a4f1501ffc7f087dec4e281e n/bind-9.18.24-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg bind-9.16.48-i586-1_slack15.0.txz Then, restart the name server: # /etc/rc.d/rc.bind restart +-----+ . A fresh bind update has been released for Slackware 15.0 to resolve urgent security vulnerabilities and improve the reliability of DNS services.. Slackware Bind Security Update, Slackware 15.0 Security, DNS Denial Of Service, Bind Package Upgrade. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2023-31137, CVE-2022-30256. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0c012f6245 2023-05-25 01:10:39.287243 --------------------------------------------------------------------------------Name : maradns Product : Fedora 38 Version : 3.5.0036 Release : 1.fc38 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-31137, CVE-2022-30256 --------------------------------------------------------------------------------ChangeLog: * Tue May 16 2023 Tomasz Torcz - 3.5.0036-1 - new version 3.5.0036 (rhbz#2149110, rhbz#2180267) - fixes CVE-2023-31137 (rhbz#2207551) --------------------------------------------------------------------------------References: [ 1 ] Bug #2207550 - CVE-2023-31137 maradns: integer underflow in DNS packet decompression https://bugzilla.redhat.com/show_bug.cgi?id=2207550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0c012f6245' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Fix CVE-2016-10152 (hardcoded DNS fallback) Fix CVE-2016-10151 (weak SUID check) Move package to autosetup Resolves: #1332509 Resolves: #1332494. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2b274689e8 2018-10-23 21:06:54.128811 --------------------------------------------------------------------------------Name : hesiod Product : Fedora 28 Version : 3.2.1 Release : 14.fc28 URL : None Summary : Shared libraries for querying the Hesiod naming service Description : Hesiod is a system which uses existing DNS functionality to provide access to databases of information that changes infrequently. It is often used to distribute information kept in the /etc/passwd, /etc/group, and /etc/printcap files, among others. --------------------------------------------------------------------------------Update Information: Fix CVE-2016-10152 (hardcoded DNS fallback) Fix CVE-2016-10151 (weak SUID check) Move package to autosetup Resolves: #1332509 Resolves: #1332494 --------------------------------------------------------------------------------ChangeLog: * Thu Oct 11 2018 Robbie Harwood - 3.2.1-14 - Fix CVE-2016-10152 (hardcoded DNS fallback) - Fix CVE-2016-10151 (weak SUID check) - Move package to autosetup * Fri Jul 13 2018 Fedora Release Engineering - 3.2.1-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri May 18 2018 Adam Williamson - 3.2.1-12 - Rebuild for new libidn --------------------------------------------------------------------------------References: [ 1 ] Bug #1332509 - hesiod: Weak SUID check allowing privilege elevation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1332509 [ 2 ] Bug #1332494 - hesiod: Use of hard-coded unsafe configuration if configuration file cannot be opened [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1332494 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-2b274689e8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fixed https://bugzilla.redhat.com/show_bug.cgi?id=1259563 https://bugzilla.redhat.com/show_bug.cgi?id=1259691. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14954 2015-09-06 17:04:34.357507 -------------------------------------------------------------------------------- Name : bind99 Product : Fedora 23 Version : 9.9.7 Release : 7.P3.fc23 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. This package set contains only export version of BIND libraries, that are used for building ISC DHCP. -------------------------------------------------------------------------------- Update Information: Fixed https://bugzilla.redhat.com/show_bug.cgi?id=1259563 https://bugzilla.redhat.com/show_bug.cgi?id=1259691 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1259085 - CVE-2015-5986 Bind: fromwire_openpgpkey() incorrect boundary check Denial of Service https://bugzilla.redhat.com/show_bug.cgi?id=1259085 [ 2 ] Bug #1259087 - CVE-2015-5722 bind: malformed DNSSEC key failed assertion denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1259087 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bind99' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.