Opened 4 months ago

Closed 3 months ago

#23332 closed enhancement (fixed)

bind9 bind 9.20.23

Reported by: Douglas R. Reno Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version. Following Xi's recommendations, I'll file a separate ticket for this one since it's another security update.

CVEs fixed include:

On 20 May 2026, Internet Systems Consortium disclosed six 
vulnerabilities affecting our BIND 9 software:

- CVE-2026-3039:        BIND 9 server memory exhaustion during GSS-API 
TKEY negotiation https://kb.isc.org/docs/cve-2026-3039
- CVE-2026-3592:        Amplification vulnerabilities via self-pointed 
glue records https://kb.isc.org/docs/cve-2026-3592
- CVE-2026-3593:        Heap use-after-free vulnerability in BIND 9 DNS-
over-HTTPS implementation https://kb.isc.org/docs/cve-2026-3593
- CVE-2026-5946:        Invalid handling of CLASS != IN 
https://kb.isc.org/docs/cve-2026-5946
- CVE-2026-5947:        SIG(0) validation during query flood may lead to 
undefined behavior https://kb.isc.org/docs/cve-2026-5947
- CVE-2026-5950:        Unbounded resend loop in BIND 9 resolver 
https://kb.isc.org/docs/cve-2026-5950

Change History (8)

comment:1 by Douglas R. Reno, 4 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by pierre, 4 months ago

Shouldn't we close #23041, then? say, as "overcomebyevents", since none of the previous versions were in the book.

comment:3 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to blfs-book
Status: assigned → new

I'm going to reassign these to the book for now so whoever wants to do them can do them.

In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.

comment:4 by pierre, 4 months ago

Owner: changed from blfs-book to pierre
Status: new → assigned

comment:6 by pierre, 4 months ago

Owner: changed from pierre to SecurityAdvisory
Status: assigned → new

Updated at aba6910d61. Leaving open for SA

comment:7 by Bruce Dubbs, 3 months ago

Milestone: 13.1 → 98-Security

comment:8 by Bruce Dubbs, 3 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-134 has been issued,

Note: See TracTickets for help on using tickets.