Opened 4 months ago
Closed 3 months ago
#23332 closed enhancement (fixed)
bind9 bind 9.20.23
| Reported by: | Douglas R. Reno | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version. Following Xi's recommendations, I'll file a separate ticket for this one since it's another security update.
CVEs fixed include:
On 20 May 2026, Internet Systems Consortium disclosed six vulnerabilities affecting our BIND 9 software: - CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation https://kb.isc.org/docs/cve-2026-3039 - CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records https://kb.isc.org/docs/cve-2026-3592 - CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS- over-HTTPS implementation https://kb.isc.org/docs/cve-2026-3593 - CVE-2026-5946: Invalid handling of CLASS != IN https://kb.isc.org/docs/cve-2026-5946 - CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior https://kb.isc.org/docs/cve-2026-5947 - CVE-2026-5950: Unbounded resend loop in BIND 9 resolver https://kb.isc.org/docs/cve-2026-5950
Change History (8)
comment:1 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 4 months ago
comment:3 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
I'm going to reassign these to the book for now so whoever wants to do them can do them.
In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 4 months ago
release notes at https://downloads.isc.org/isc/bind9/9.20.23/doc/arm/html/notes.html
comment:6 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Updated at aba6910d61. Leaving open for SA
comment:7 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|
comment:8 by , 3 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-134 has been issued,
Note:
See TracTickets
for help on using tickets.

Shouldn't we close #23041, then? say, as "overcomebyevents", since none of the previous versions were in the book.