Pick patch from [1], [2] & [3] also mentioned at Debian report in [4] [1] https://gitlab.isc.org/isc-projects/bind9/-/commit/adc8285d23e2eac6ec463f5dbc5a9596fdd36c60 [2] https://gitlab.isc.org/isc-projects/bind9/-/commit/095b11f20f911f5b8059bdc349b256d6c64ece30 [3] https://gitlab.isc.org/isc-projects/bind9/-/commit/dc328a199f96222e0c30cc20b7b795bfc2c9b2e4 [4] https://security-tracker.debian.org/tracker/CVE-2026-11331
Signed-off-by: Hitendra Prajapati <[email protected]> --- .../bind/bind/CVE-2026-11331-01.patch | 30 ++++++++++ .../bind/bind/CVE-2026-11331-02.patch | 58 +++++++++++++++++++ .../bind/bind/CVE-2026-11331-03.patch | 34 +++++++++++ .../recipes-connectivity/bind/bind_9.18.49.bb | 3 + 4 files changed, 125 insertions(+) create mode 100644 meta/recipes-connectivity/bind/bind/CVE-2026-11331-01.patch create mode 100644 meta/recipes-connectivity/bind/bind/CVE-2026-11331-02.patch create mode 100644 meta/recipes-connectivity/bind/bind/CVE-2026-11331-03.patch diff --git a/meta/recipes-connectivity/bind/bind/CVE-2026-11331-01.patch b/meta/recipes-connectivity/bind/bind/CVE-2026-11331-01.patch new file mode 100644 index 0000000000..1aaca7392a --- /dev/null +++ b/meta/recipes-connectivity/bind/bind/CVE-2026-11331-01.patch @@ -0,0 +1,30 @@ +From: Mark Andrews <[email protected]> +Date: Fri, 10 Apr 2026 10:24:06 +1000 +Subject: Fix TTL extraction from A/AAAA record + +(cherry picked from commit 89c86e338db2492b92e6618c586f146c6928dc6d) + +Origin: https://gitlab.isc.org/isc-projects/bind9/-/commit/adc8285d23e2eac6ec463f5dbc5a9596fdd36c60 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-11331 +Bug-Freexian-Security: https://deb.freexian.com/extended-lts/tracker/CVE-2026-11331 + +CVE: CVE-2026-11331 +Upstream-Status: Backport [https://gitlab.isc.org/isc-projects/bind9/-/commit/adc8285d23e2eac6ec463f5dbc5a9596fdd36c60] +Signed-off-by: Hitendra Prajapati <[email protected]> +--- + bin/tests/system/rpz/tests.sh | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/bin/tests/system/rpz/tests.sh b/bin/tests/system/rpz/tests.sh +index 87e4118..90cf80c 100644 +--- a/bin/tests/system/rpz/tests.sh ++++ b/bin/tests/system/rpz/tests.sh +@@ -391,7 +391,7 @@ addr() { + digcmd $2 >$DIGNM + #ckalive "$2" "server crashed by 'dig $2'" || return 1 + ADDR_ESC=$(echo "$ADDR" | sed -e 's/\./\\./g') +- ADDR_TTL=$(sed -n -e "s/^[-.a-z0-9]\{1,\}[ ]*\([0-9]*\) IN AA* ${ADDR_ESC}\$/\1/p" $DIGNM) ++ ADDR_TTL=$(sed -n -e "s/^[-.a-z0-9]\{1,\}[ ]*\([0-9]*\)[ ]IN[ ]AA*[ ]${ADDR_ESC}\$/\1/p" $DIGNM) + if test -z "$ADDR_TTL"; then + setret "'dig $2' wrong; no address $ADDR record in $DIGNM" + return 0 diff --git a/meta/recipes-connectivity/bind/bind/CVE-2026-11331-02.patch b/meta/recipes-connectivity/bind/bind/CVE-2026-11331-02.patch new file mode 100644 index 0000000000..8f45d7021b --- /dev/null +++ b/meta/recipes-connectivity/bind/bind/CVE-2026-11331-02.patch @@ -0,0 +1,58 @@ +From: Mark Andrews <[email protected]> +Date: Fri, 10 Apr 2026 10:24:40 +1000 +Subject: Check rpz name too long wildcard CNAME expansion handling + +(cherry picked from commit 9345394e2097031b55b3ef34ceaadf5a7ebbeef2) + +Origin: https://gitlab.isc.org/isc-projects/bind9/-/commit/095b11f20f911f5b8059bdc349b256d6c64ece30 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-11331 +Bug-Freexian-Security: https://deb.freexian.com/extended-lts/tracker/CVE-2026-11331 + +CVE: CVE-2026-11331 +Upstream-Status: Backport [https://gitlab.isc.org/isc-projects/bind9/-/commit/095b11f20f911f5b8059bdc349b256d6c64ece30] +Signed-off-by: Hitendra Prajapati <[email protected]> +--- + bin/tests/system/rpz/ns2/tld2.db | 2 ++ + bin/tests/system/rpz/ns4/tld4.db | 2 ++ + bin/tests/system/rpz/tests.sh | 5 ++++- + 3 files changed, 8 insertions(+), 1 deletion(-) + +diff --git a/bin/tests/system/rpz/ns2/tld2.db b/bin/tests/system/rpz/ns2/tld2.db +index c6f2556..c091ee2 100644 +--- a/bin/tests/system/rpz/ns2/tld2.db ++++ b/bin/tests/system/rpz/ns2/tld2.db +@@ -123,3 +123,5 @@ a7-1 A 192.168.7.1 + + a7-2 A 192.168.7.2 + TXT "a7-2 tld2 text" ++ ++*.wild A 192.168.9.1 +diff --git a/bin/tests/system/rpz/ns4/tld4.db b/bin/tests/system/rpz/ns4/tld4.db +index fca419c..8accd76 100644 +--- a/bin/tests/system/rpz/ns4/tld4.db ++++ b/bin/tests/system/rpz/ns4/tld4.db +@@ -59,6 +59,8 @@ a3-6.tld2 A 56.56.56.56 + + a3-7.sub1.tld2 A 57.57.57.57 + ++*.wild.sub1.tld2 A 57.57.57.57 ++ + a3-8.tld2 A 58.58.58.58 + + a3-9.sub9.tld2 A 59.59.59.59 +diff --git a/bin/tests/system/rpz/tests.sh b/bin/tests/system/rpz/tests.sh +index 90cf80c..5297437 100644 +--- a/bin/tests/system/rpz/tests.sh ++++ b/bin/tests/system/rpz/tests.sh +@@ -516,7 +516,10 @@ nochange TCP a3-9.tld2 # 33 tcp-only + here x.servfail <<'EOF' # 34 qname-wait-recurse yes + ;; status: SERVFAIL, x + EOF +-addr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no ++addr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no ++here aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.wild.sub1.tld2 <<'EOF' # 36 wildcard CNAME name to long ++ ;; status: YXDOMAIN, x ++EOF + end_group + ckstats $ns3 test1 ns3 22 + ckstats $ns5 test1 ns5 1 diff --git a/meta/recipes-connectivity/bind/bind/CVE-2026-11331-03.patch b/meta/recipes-connectivity/bind/bind/CVE-2026-11331-03.patch new file mode 100644 index 0000000000..2d57122632 --- /dev/null +++ b/meta/recipes-connectivity/bind/bind/CVE-2026-11331-03.patch @@ -0,0 +1,34 @@ +From: Mark Andrews <[email protected]> +Date: Fri, 10 Apr 2026 10:26:14 +1000 +Subject: Properly handle rpz name to long wildcard expansion + +Previously a self referential CNAME and the original address +record were returned. We now return a YXDOMAIN response. + +(cherry picked from commit cfc4c4f69870ce492deaaa429453563d1621ded3) + +Origin: https://gitlab.isc.org/isc-projects/bind9/-/commit/dc328a199f96222e0c30cc20b7b795bfc2c9b2e4 +Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-11331 +Bug-Freexian-Security: https://deb.freexian.com/extended-lts/tracker/CVE-2026-11331 + +CVE: CVE-2026-11331 +Upstream-Status: Backport [https://gitlab.isc.org/isc-projects/bind9/-/commit/dc328a199f96222e0c30cc20b7b795bfc2c9b2e4] +Signed-off-by: Hitendra Prajapati <[email protected]> +--- + lib/ns/query.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/lib/ns/query.c b/lib/ns/query.c +index 86485b7..f0e5244 100644 +--- a/lib/ns/query.c ++++ b/lib/ns/query.c +@@ -7579,7 +7579,8 @@ query_rpzcname(query_ctx_t *qctx, dns_name_t *cname) { + qctx->fname, NULL); + if (result == DNS_R_NAMETOOLONG) { + client->message->rcode = dns_rcode_yxdomain; +- } else if (result != ISC_R_SUCCESS) { ++ } ++ if (result != ISC_R_SUCCESS) { + return result; + } + } else { diff --git a/meta/recipes-connectivity/bind/bind_9.18.49.bb b/meta/recipes-connectivity/bind/bind_9.18.49.bb index 42007383c4..dc274f6076 100644 --- a/meta/recipes-connectivity/bind/bind_9.18.49.bb +++ b/meta/recipes-connectivity/bind/bind_9.18.49.bb @@ -26,6 +26,9 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \ file://CVE-2026-10822-03.patch \ file://CVE-2026-10822-04.patch \ file://CVE-2026-10822-05.patch \ + file://CVE-2026-11331-01.patch \ + file://CVE-2026-11331-02.patch \ + file://CVE-2026-11331-03.patch \ " SRC_URI[sha256sum] = "c43ce4548ebed788cd9df63658a7de105ceafba43fcd63fa352b1093e525cd24" -- 2.50.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246733): https://lists.openembedded.org/g/openembedded-core/message/246733 Mute This Topic: https://lists.openembedded.org/mt/121467730/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
