Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package bind for openSUSE:Factory checked in at 2026-09-29 17:46:52 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/bind (Old) and /work/SRC/openSUSE:Factory/.bind.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "bind" Tue Sep 29 17:46:52 2026 rev:236 rq:1381163 version:9.20.29 Changes: -------- --- /work/SRC/openSUSE:Factory/bind/bind.changes 2026-07-26 11:29:38.713116329 +0200 +++ /work/SRC/openSUSE:Factory/.bind.new.383539/bind.changes 2026-09-29 17:47:57.329643943 +0200 @@ -1,0 +2,106 @@ +Mon Sep 28 12:50:48 UTC 2026 - Jorik Cronenberg <[email protected]> + +- Update named.root + +------------------------------------------------------------------- +Mon Sep 28 12:10:01 UTC 2026 - Jorik Cronenberg <[email protected]> + +- Upgrade to release 9.20.29 + Security Fixes: + * Prevent excessive CPU use validating crafted DNSSEC responses. + (CVE-2026-19668) + [bsc#1280436] + * Require a TSIG on every message of incoming zone transfers. + (CVE-2026-19033) + [bsc#1280430] + * Prevent a DNSSEC downgrade of secure delegations via unrelated + NSEC3 records. + (CVE-2026-77119) + [bsc#1280440] + * Prevent forged DNSSEC-validated NXDOMAIN responses. + (CVE-2026-19941) + [bsc#1280437] + * DNS64 with break-dnssec could cause an assertion failure. + (CVE-2026-19666) + [bsc#1280433] + * Reject oversized negative cache records. + (CVE-2026-19667) + [bsc#1280435] + * Prevent resolver crash with cached DNSSEC proofs. + (CVE-2026-19662) + [bsc#1280432] + * Discard repeated SOA, CNAME, and DNAME records when parsing DNS + messages. + (CVE-2026-75029) + [bsc#1280438] + * Fix an unauthenticated crash on HTTPS using SIG(0). + (CVE-2026-77692) + [bsc#1280441] + * Cached HTTPS/SVCB aliases could exhaust resolver CPU. + (CVE-2026-81736) + [bsc#1280445] + * Prevent TKEY queries from terminating named without global + options. + (CVE-2026-76163) + [bsc#1280439] + * Out-of-zone records in a zone database could be served as + authoritative. + (CVE-2026-78301) + [bsc#1280442] + * Fix crash on wildcard answers carrying both NSEC and NSEC3 + proofs. + (CVE-2026-80274) + [bsc#1280443] + * Following HTTPS/SVCB aliases could leak resolver cache memory. + (CVE-2026-81563) + [bsc#1280444] + + New Features: + * Disclose active Negative Trust Anchors with Extended DNS Error + 33. + + Feature Changes: + * Reject oversized and malformed DNSKEY records up front. + * Speed up RPZ policy zone updates. + + Bug Fixes: + * Prevent a crash when using both dns64 and filter-a. + * Stop passing UDP client addresses to update-policy external + helpers. + * Missing required NSEC3 for delegation not detected. + * Tighten EUI48 and EUI64 text parsing. + * GeoIP ACL state could be stale or wrong after reload. + * Honor DNSSEC policy key tag ranges. + * Fix a double free in mdig when EDNS options are specified. + * Fix a crash when an IXFR falls back to AXFR with updates still + pending. + * Fix DS requests to parental agents over TLS. + * Fix the rndc-confgen -q (quiet) option. + * Enforce query ACLs for redirect zones and searched DLZs. + * Check asnum validity in GeoIP ACLs. + * Fix a crash on remote-servers lists that reference themselves. + * A record from outside a response policy zone could crash named. + * Invalid key-store configuration could abort the DNSSEC tools. + * NSEC signature set could bypass the secure-delegation check. + * Fix a possible nsupdate issue when using GSS-TSIG. + * Fix a crash with a single-element geoip sortlist. + * Prevent out-of-bailiwick CNAMEs from evicting cached records. + * Restore periodic cleanup of stale resolver address data. + * Fix named-checkconf/named crash with malformed key name. + * Prevent resolver crashes while processing DNS over TCP. + * Ensure NSEC authority does not cross zonecut boundary. + * Treat an unusable NSEC3 chain as a verification failure. + * Treat non-canonical RPZ prefixes as any other failure. + * Negative caching stopped working with + stale-answer-client-timeout set to 0. + * An unterminated OpenSSL private-key Label: field could be read + past its parser buffer. + * Restore SMF support on Solaris and illumos. + * Fix compilation on GNU/Hurd. + * dig +yaml was producing invalid YAML when a lookup failed. + * Properly prevent TSIG generation command line injection + attacks. + * Fix a potential heap bounds overflow write in dnssec-signzone. + * Fix crashes on invalid DNSTAP input in dnstap-read. + +------------------------------------------------------------------- Old: ---- bind-9.20.26.tar.xz bind-9.20.26.tar.xz.asc New: ---- bind-9.20.29.tar.xz bind-9.20.29.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ bind.spec ++++++ --- /var/tmp/diff_new_pack.zUb4U2/_old 2026-09-29 17:47:58.623698079 +0200 +++ /var/tmp/diff_new_pack.zUb4U2/_new 2026-09-29 17:47:58.626698204 +0200 @@ -34,7 +34,7 @@ %define dlz_modules_hash 5923650 Name: bind -Version: 9.20.26 +Version: 9.20.29 Release: 0 Summary: Domain Name System (DNS) Server (named) License: MPL-2.0 ++++++ bind-9.20.26.tar.xz -> bind-9.20.29.tar.xz ++++++ ++++ 72741 lines of diff (skipped) ++++++ named.root ++++++ --- /var/tmp/diff_new_pack.zUb4U2/_old 2026-09-29 17:48:00.850791247 +0200 +++ /var/tmp/diff_new_pack.zUb4U2/_new 2026-09-29 17:48:00.855791456 +0200 @@ -9,8 +9,8 @@ ; on server FTP.INTERNIC.NET ; -OR- RS.INTERNIC.NET ; -; last update: December 18, 2024 -; related version of root zone: 2024121801 +; last update: September 24, 2026 +; related version of root zone: 2026092401 ; ; FORMERLY NS.INTERNIC.NET ;
