[Git][security-tracker-team/security-tracker][master] Adjust tracking for bind9 in CVE-2026-10822

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 9 06:02:58 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd290ac1 by Salvatore Bonaccorso at 2026-08-09T07:00:59+02:00
Adjust tracking for bind9 in CVE-2026-10822

The issue was not affecting bullseye (vulnerable not present according
to triage). This means only bookworm was addressed in the DLA 4725-1 for
this CVE. If the version is listed as well for bullseye this will imply
the issue was present before and only fixed with 1:9.16.50-1~deb11u6.

Move tracking of the fixed version for bookworm directly in the CVE list
and drop the CVE from the DLA list.

- - - - -


2 changed files:

- data/CVE/list
- data/DLA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13602,8 +13602,9 @@ CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, whi
 	NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/35e3d49d2222c13786a06021c7ed583d2a656e51 (9.18-branch)
 	NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/833dd3b230b92596074e8da15b12298f46c939f2 (9.18-branch)
 CVE-2026-10822 (If BIND encounters a particular invalid data structure in a DNS record ...)
-	{DSA-6395-1 DLA-4725-1}
+	{DSA-6395-1}
 	- bind9 1:9.20.26-1
+	[bookworm] - bind9 1:9.18.49-1~deb12u2
 	[bullseye] - bind9 <not-affected> (Vulnerable code not present)
 	NOTE: https://kb.isc.org/docs/cve-2026-10822
 	NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/d413c9ac2e29a728531354a69c8c8234c01b7d1e (9.18-branch)


=====================================
data/DLA/list
=====================================
@@ -1,5 +1,5 @@
 [07 Aug 2026] DLA-4725-1 bind9 - security update
-	{CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321}
+	{CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321}
 	[bullseye] - bind9 1:9.16.50-1~deb11u6
 	[bookworm] - bind9 1:9.18.49-1~deb12u2
 [07 Aug 2026] DLA-4724-1 linux-6.12 - security update



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd290ac19c22a5227031765290956fe06d51ea77

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd290ac19c22a5227031765290956fe06d51ea77
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/a7871eae/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list