-------------------------------------------------------------------------
Debian LTS Advisory DLA-4725-1                [email protected]
https://www.debian.org/lts/security/                       Emmanuel Arias
August 08, 2026                               https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : bind9
Version        : 1:9.16.50-1~deb11u6 1:9.18.49-1~deb12u2
CVE ID         : CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950
                 CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605
                 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204
                 CVE-2026-13321

Several vulnerabilities were found in bind9, a DNS server implementation, which
may lead to denial of service, DNSSEC validation bypass, cache poisoning or RPZ
policy bypass.

CVE-2026-3039

    Servers configured for TKEY authentication using GSS-API tokens can be
    driven into unbounded memory growth while parsing specially crafted packets.
    Such setups are common in Active Directory integrated DNS deployments and in
    Kerberos-secured DNS environments.

CVE-2026-3592

    A resolver querying a specially crafted zone ends up doing far more work
    than the original query would justify, which an attacker can abuse as an
    amplified resource exhaustion vector.

CVE-2026-5946

    A group of related defects was found in the way named processes DNS messages
    carrying a CLASS other than Internet (IN), as well as messages using the
    meta-classes ANY or NONE in the question section.

CVE-2026-5950

    While handling misbehaving servers, the resolver state machine could enter a
    resend loop with no upper bound. A remote, unauthenticated attacker able to
    trigger those retry conditions can exhaust the service's resources.

CVE-2026-10723

    The signer name of NSEC3 records was not checked correctly, so named could
    treat bogus child-zone NSEC3 records as legitimate. This opened the door to
    forged NXDOMAIN answers that appear authenticated.

CVE-2026-10822

    A malformed DNSKEY record could reach an assertion. When BIND ran into such
    an invalid data structure it accepted it and stored the bogus identifier,
    and could later abort and terminate.

CVE-2026-11331

    RPZ processing of wildcard CNAME policies could produce a name exceeding the
    maximum length. An attacker aware (or merely suspecting) that a resolver
    applies such policies can craft query names long enough to hit the resulting
    NAMETOOLONG error condition.

CVE-2026-11605

    A validating resolver could be made to spend a disproportionate amount of
    CPU time on DNSSEC validation for a single answer, verifying signatures that
    were never needed. A malicious authoritative server returning unsolicited or
    superfluous RRSIG records is enough to trigger it.

CVE-2026-11622

    A DNSSEC-validating resolver targeted by a random subdomain attack against a
    signed zone could keep growing its memory footprint without bound,
    exhausting the cache.

CVE-2026-11721

    An attacker-controlled zone could answer with an RRSIG whose label count is
    lower than that of the zone holding it. Such invalid signed wildcard records
    are no longer accepted.

CVE-2026-12617

    Depending on the ordering and the exact contents of the answers returned for
    CNAME or DNAME queries together with A records, named could reach an
    assertion and terminate unexpectedly.

CVE-2026-13204

    When a provably insecure domain is covered at the parent by both an NSEC
    and an NSEC3 record but only one of the two types carries an RRSIG,
    validating that proof could make BIND hit an assertion and exit.

CVE-2026-13321

    The resolver accepted properly signed NSEC records whose 'Next Domain
    Name' field points outside the signer's zone, which could be used to
    bypass DNSSEC validation.

For Debian 11 bullseye, these problems have been fixed in version
1:9.16.50-1~deb11u6.

For Debian 12 bookworm, these problems have been fixed in version
1:9.18.49-1~deb12u2.

We recommend that you upgrade your bind9 packages.

For the detailed security status of bind9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/bind9

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to