Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package bind for openSUSE:Factory checked in 
at 2026-05-28 17:23:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/bind (Old)
 and      /work/SRC/openSUSE:Factory/.bind.new.1937 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "bind"

Thu May 28 17:23:58 2026 rev:232 rq:1355340 version:9.20.23

Changes:
--------
--- /work/SRC/openSUSE:Factory/bind/bind.changes        2026-04-16 
17:25:26.503657150 +0200
+++ /work/SRC/openSUSE:Factory/.bind.new.1937/bind.changes      2026-05-28 
17:24:30.017661786 +0200
@@ -1,0 +2,23 @@
+Tue May 26 16:02:53 UTC 2026 - Reinhard Max <[email protected]>
+
+- Upgrade to release 9.20.23
+  https://downloads.isc.org/isc/bind9/9.20.23/doc/arm/html/notes.html
+  Security-Fixes:
+  * Amplification vulnerabilities via self-pointed glue records.
+    (CVE-2026-3592)
+    [bsc#1265592]
+  * server memory exhaustion during GSS-API TKEY negotiation.
+    (CVE-2026-3039)
+    [bsc#1265591]
+  * Unbounded resend loop in BIND 9 resolver
+    (CVE-2026-5950)
+    [bsc#1265596]
+  * SIG(0) validation during query flood may lead to undefined
+    behavior.
+    (CVE-2026-5947)
+    [bsc#1265595]
+  * Invalid handling of CLASS != IN.
+    (CVE-2026-5946)
+    [bsc#1265594]
+
+-------------------------------------------------------------------

Old:
----
  bind-9.20.22.tar.xz
  bind-9.20.22.tar.xz.asc

New:
----
  bind-9.20.23.tar.xz
  bind-9.20.23.tar.xz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ bind.spec ++++++
--- /var/tmp/diff_new_pack.Zfea9H/_old  2026-05-28 17:24:31.121707486 +0200
+++ /var/tmp/diff_new_pack.Zfea9H/_new  2026-05-28 17:24:31.125707651 +0200
@@ -34,7 +34,7 @@
 %define dlz_modules_hash 5923650
 
 Name:           bind
-Version:        9.20.22
+Version:        9.20.23
 Release:        0
 Summary:        Domain Name System (DNS) Server (named)
 License:        MPL-2.0

++++++ bind-9.20.22.tar.xz -> bind-9.20.23.tar.xz ++++++
++++ 12338 lines of diff (skipped)

Reply via email to