This bug was fixed in the package bind9 - 1:9.20.24-1ubuntu0.1
---------------
bind9 (1:9.20.24-1ubuntu0.1) resolute; urgency=medium
* New upstream release 9.20.24 (LP: #2126464)
- Updates:
+ Remove the ineffective TCP fallback after repeated UDP timeouts.
+ Fall back to TCP on receipt of a UDP response with mismatched query ID.
+ Limit glue records cached from a referral per nameserver.
+ Reject a CNAME response to a DS query promptly.
+ Spread cache cleanup probabilistically to avoid CPU spikes and slow
queries when the cache approaches its memory limit.
+ Record query time for all dnstap responses.
+ Optimize TCP source port selection on Linux via IP_LOCAL_PORT_RANGE.
+ Use the zone file's basename as origin in dnssec-signzone and
dnssec-verify.
+ Implement seamless outgoing TCP connection reuse with pipelined queries
per connection capped at 256.
+ Randomize nameserver selection.
+ Make catalog zone names and member zones' entry names case-insensitive.
- Bug fixes:
+ Remove other RRsets at the same name when caching a CNAME.
+ Fix nxdomain-redirect combined with dns64.
+ Fix DNS64 owner-name case after a DNAME restart.
+ Clear the REDIRECT flag when it isn't needed.
+ Disable output escaping in bind9.xsl.
+ Fix crash on badly configured secondary signer missing the file entry.
+ Fix possible crash on concurrent TKEY DELETE for the same key.
+ Reject RRSIG records covering meta-types ANY, AXFR, IXFR, MAILA, MAILB.
+ Fix possible race condition during zone transfers.
+ Fix named crash when processing SIG records in dynamic updates.
+ Fix zone verification of NSEC3 signed zones.
+ Prevent a crash when using both dns64 and filter-aaaa.
+ Fix assertion failure when processing catalog zones with invalid TSIG
key name.
+ Prevent malicious DNSSEC zones from exhausting validator CPU by
rejecting DNSKEYs with oversized RSA public exponent.
+ Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits.
+ Prevent crafted queries from degrading RRL performance via
per-process keyed hash.
+ Prevent rare named crash when notifies are cancelled.
+ Stop delv from aborting on malformed query name.
+ Fix crash when reconfiguring while an NTA is being rechecked.
+ Fix bug in allow-query/allow-transfer catalog zone custom properties.
+ Fix memory leak in catalog zones.
+ Fix suppressed missing-glue check in named-checkzone.
+ Reject record sets too large to serve in DNS at storage time.
+ Fix intermittent named crashes during asynchronous zone operations by
enforcing loop affinity.
+ Count temporal DNSSEC validation problems as validation attempts.
+ Fix possible deadlock in RPZ processing.
+ Fix crash triggered by rndc modzone on a zone from a configuration
file.
+ Fix processing of empty catalog zone ACLs.
+ Fix crash triggered by rndc modzone on a zone that already existed in
NZF file.
+ Fix potential resource leak during resolver error handling.
+ Fix handling of key statements defined inside views.
+ Fix use-after-free in dns_client_resolve() triggered by a DNAME
response.
+ Fix assertion failure triggered by non-minimal IXFRs.
+ Fix crash when retrying a NOTIFY over TCP.
+ Improve fetch loop detection for an in-domain nameserver with expired
glue.
+ Fix dnstap logging of forwarded queries.
+ Fix stale answer being served on multiple upstream failures when
following CNAME chains.
+ Fail DNSKEY validation when supported but invalid DS is found..
+ Fix stack memory corruption when importing invalid SKR file.
+ Return FORMERR for queries with EDNS Client Subnet FAMILY field set to
0.
+ Fix inbound IXFR performance regression where very large IXFR
transfers were much slower than in 9.18.
+ Fix implementation of BRID and HHIT record types.
+ Fix implementation of DSYNC record type.
+ Fix response policy and catalog zones to work with INCLUDE directive.
- Remove CVE patches fixed upstream
+ CVE-2026-1519-*.patch
+ CVE-2026-3104-*.patch
+ CVE-2026-3119-*.patch
+ CVE-2026-3591-*.patch
[Fixed in 9.20.21]
+ CVE-2026-3039-*.patch
+ CVE-2026-3592-*.patch
+ CVE-2026-3593-*.patch
+ CVE-2026-5946-*.patch
+ CVE-2026-5947.patch
+ CVE-2026-5950-*.patch
[Fixed in 9.20.23]
-- Lena Voytek <[email protected]> Mon, 13 Jul 2026 14:38:03
-0400
** Changed in: bind9 (Ubuntu Resolute)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-1519
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3039
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3104
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3119
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3591
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3592
** CVE added: https://cve.org/CVERecord?id=CVE-2026-3593
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5946
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5947
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5950
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2126464
Title:
Backport of bind9 for resolute, noble, and jammy
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/bind-dyndb-ldap/+bug/2126464/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs