------------------------------------------------------------------------- Debian LTS Advisory DLA-4725-1 [email protected] https://www.debian.org/lts/security/ Emmanuel Arias August 08, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : bind9
Version : 1:9.16.50-1~deb11u6 1:9.18.49-1~deb12u2
CVE ID : CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950
CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605
CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204
CVE-2026-13321
Several vulnerabilities were found in bind9, a DNS server implementation, which
may lead to denial of service, DNSSEC validation bypass, cache poisoning or RPZ
policy bypass.
CVE-2026-3039
Servers configured for TKEY authentication using GSS-API tokens can be
driven into unbounded memory growth while parsing specially crafted packets.
Such setups are common in Active Directory integrated DNS deployments and in
Kerberos-secured DNS environments.
CVE-2026-3592
A resolver querying a specially crafted zone ends up doing far more work
than the original query would justify, which an attacker can abuse as an
amplified resource exhaustion vector.
CVE-2026-5946
A group of related defects was found in the way named processes DNS messages
carrying a CLASS other than Internet (IN), as well as messages using the
meta-classes ANY or NONE in the question section.
CVE-2026-5950
While handling misbehaving servers, the resolver state machine could enter a
resend loop with no upper bound. A remote, unauthenticated attacker able to
trigger those retry conditions can exhaust the service's resources.
CVE-2026-10723
The signer name of NSEC3 records was not checked correctly, so named could
treat bogus child-zone NSEC3 records as legitimate. This opened the door to
forged NXDOMAIN answers that appear authenticated.
CVE-2026-10822
A malformed DNSKEY record could reach an assertion. When BIND ran into such
an invalid data structure it accepted it and stored the bogus identifier,
and could later abort and terminate.
CVE-2026-11331
RPZ processing of wildcard CNAME policies could produce a name exceeding the
maximum length. An attacker aware (or merely suspecting) that a resolver
applies such policies can craft query names long enough to hit the resulting
NAMETOOLONG error condition.
CVE-2026-11605
A validating resolver could be made to spend a disproportionate amount of
CPU time on DNSSEC validation for a single answer, verifying signatures that
were never needed. A malicious authoritative server returning unsolicited or
superfluous RRSIG records is enough to trigger it.
CVE-2026-11622
A DNSSEC-validating resolver targeted by a random subdomain attack against a
signed zone could keep growing its memory footprint without bound,
exhausting the cache.
CVE-2026-11721
An attacker-controlled zone could answer with an RRSIG whose label count is
lower than that of the zone holding it. Such invalid signed wildcard records
are no longer accepted.
CVE-2026-12617
Depending on the ordering and the exact contents of the answers returned for
CNAME or DNAME queries together with A records, named could reach an
assertion and terminate unexpectedly.
CVE-2026-13204
When a provably insecure domain is covered at the parent by both an NSEC
and an NSEC3 record but only one of the two types carries an RRSIG,
validating that proof could make BIND hit an assertion and exit.
CVE-2026-13321
The resolver accepted properly signed NSEC records whose 'Next Domain
Name' field points outside the signer's zone, which could be used to
bypass DNSSEC validation.
For Debian 11 bullseye, these problems have been fixed in version
1:9.16.50-1~deb11u6.
For Debian 12 bookworm, these problems have been fixed in version
1:9.18.49-1~deb12u2.
We recommend that you upgrade your bind9 packages.
For the detailed security status of bind9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/bind9
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
signature.asc
Description: PGP signature
