﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
23332	bind9 bind 9.20.23	Douglas R. Reno	SecurityAdvisory	"New point version. Following Xi's recommendations, I'll file a separate ticket for this one since it's another security update.

CVEs fixed include:

{{{
On 20 May 2026, Internet Systems Consortium disclosed six 
vulnerabilities affecting our BIND 9 software:

- CVE-2026-3039:        BIND 9 server memory exhaustion during GSS-API 
TKEY negotiation https://kb.isc.org/docs/cve-2026-3039
- CVE-2026-3592:        Amplification vulnerabilities via self-pointed 
glue records https://kb.isc.org/docs/cve-2026-3592
- CVE-2026-3593:        Heap use-after-free vulnerability in BIND 9 DNS-
over-HTTPS implementation https://kb.isc.org/docs/cve-2026-3593
- CVE-2026-5946:        Invalid handling of CLASS != IN 
https://kb.isc.org/docs/cve-2026-5946
- CVE-2026-5947:        SIG(0) validation during query flood may lead to 
undefined behavior https://kb.isc.org/docs/cve-2026-5947
- CVE-2026-5950:        Unbounded resend loop in BIND 9 resolver 
https://kb.isc.org/docs/cve-2026-5950
}}}"	enhancement	closed	high	98-Security	BOOK	git	medium	fixed		
