This bug was fixed in the package bind9 - 1:9.20.24-1ubuntu0.1

---------------
bind9 (1:9.20.24-1ubuntu0.1) resolute; urgency=medium

  * New upstream release 9.20.24 (LP: #2126464)
    - Updates:
      + Remove the ineffective TCP fallback after repeated UDP timeouts.
      + Fall back to TCP on receipt of a UDP response with mismatched query ID.
      + Limit glue records cached from a referral per nameserver.
      + Reject a CNAME response to a DS query promptly.
      + Spread cache cleanup probabilistically to avoid CPU spikes and slow
        queries when the cache approaches its memory limit.
      + Record query time for all dnstap responses.
      + Optimize TCP source port selection on Linux via IP_LOCAL_PORT_RANGE.
      + Use the zone file's basename as origin in dnssec-signzone and
        dnssec-verify.
      + Implement seamless outgoing TCP connection reuse with pipelined queries
        per connection capped at 256.
      + Randomize nameserver selection.
      + Make catalog zone names and member zones' entry names case-insensitive.
    - Bug fixes:
      + Remove other RRsets at the same name when caching a CNAME.
      + Fix nxdomain-redirect combined with dns64.
      + Fix DNS64 owner-name case after a DNAME restart.
      + Clear the REDIRECT flag when it isn't needed.
      + Disable output escaping in bind9.xsl.
      + Fix crash on badly configured secondary signer missing the file entry.
      + Fix possible crash on concurrent TKEY DELETE for the same key.
      + Reject RRSIG records covering meta-types ANY, AXFR, IXFR, MAILA, MAILB.
      + Fix possible race condition during zone transfers.
      + Fix named crash when processing SIG records in dynamic updates.
      + Fix zone verification of NSEC3 signed zones.
      + Prevent a crash when using both dns64 and filter-aaaa.
      + Fix assertion failure when processing catalog zones with invalid TSIG
        key name.
      + Prevent malicious DNSSEC zones from exhausting validator CPU by
        rejecting DNSKEYs with oversized RSA public exponent.
      + Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits.
      + Prevent crafted queries from degrading RRL performance via
        per-process keyed hash.
      + Prevent rare named crash when notifies are cancelled.
      + Stop delv from aborting on malformed query name.
      + Fix crash when reconfiguring while an NTA is being rechecked.
      + Fix bug in allow-query/allow-transfer catalog zone custom properties.
      + Fix memory leak in catalog zones.
      + Fix suppressed missing-glue check in named-checkzone.
      + Reject record sets too large to serve in DNS at storage time.
      + Fix intermittent named crashes during asynchronous zone operations by
        enforcing loop affinity.
      + Count temporal DNSSEC validation problems as validation attempts.
      + Fix possible deadlock in RPZ processing.
      + Fix crash triggered by rndc modzone on a zone from a configuration
        file.
      + Fix processing of empty catalog zone ACLs.
      + Fix crash triggered by rndc modzone on a zone that already existed in
        NZF file.
      + Fix potential resource leak during resolver error handling.
      + Fix handling of key statements defined inside views.
      + Fix use-after-free in dns_client_resolve() triggered by a DNAME
        response.
      + Fix assertion failure triggered by non-minimal IXFRs.
      + Fix crash when retrying a NOTIFY over TCP.
      + Improve fetch loop detection for an in-domain nameserver with expired
        glue.
      + Fix dnstap logging of forwarded queries.
      + Fix stale answer being served on multiple upstream failures when
        following CNAME chains.
      + Fail DNSKEY validation when supported but invalid DS is found..
      + Fix stack memory corruption when importing invalid SKR file.
      + Return FORMERR for queries with EDNS Client Subnet FAMILY field set to
        0.
      + Fix inbound IXFR performance regression where very large IXFR
        transfers were much slower than in 9.18.
      + Fix implementation of BRID and HHIT record types.
      + Fix implementation of DSYNC record type.
      + Fix response policy and catalog zones to work with INCLUDE directive.
    - Remove CVE patches fixed upstream
      + CVE-2026-1519-*.patch
      + CVE-2026-3104-*.patch
      + CVE-2026-3119-*.patch
      + CVE-2026-3591-*.patch
      [Fixed in 9.20.21]
      + CVE-2026-3039-*.patch
      + CVE-2026-3592-*.patch
      + CVE-2026-3593-*.patch
      + CVE-2026-5946-*.patch
      + CVE-2026-5947.patch
      + CVE-2026-5950-*.patch
      [Fixed in 9.20.23]

 -- Lena Voytek <[email protected]>  Mon, 13 Jul 2026 14:38:03
-0400

** Changed in: bind9 (Ubuntu Resolute)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-1519

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3039

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3104

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3119

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3591

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3592

** CVE added: https://cve.org/CVERecord?id=CVE-2026-3593

** CVE added: https://cve.org/CVERecord?id=CVE-2026-5946

** CVE added: https://cve.org/CVERecord?id=CVE-2026-5947

** CVE added: https://cve.org/CVERecord?id=CVE-2026-5950

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2126464

Title:
  Backport of bind9 for resolute, noble, and jammy

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/bind-dyndb-ldap/+bug/2126464/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to