[Git][security-tracker-team/security-tracker][master] Adjust tracking for bind9 in CVE-2026-10822
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 9 06:02:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fd290ac1 by Salvatore Bonaccorso at 2026-08-09T07:00:59+02:00
Adjust tracking for bind9 in CVE-2026-10822
The issue was not affecting bullseye (vulnerable not present according
to triage). This means only bookworm was addressed in the DLA 4725-1 for
this CVE. If the version is listed as well for bullseye this will imply
the issue was present before and only fixed with 1:9.16.50-1~deb11u6.
Move tracking of the fixed version for bookworm directly in the CVE list
and drop the CVE from the DLA list.
- - - - -
2 changed files:
- data/CVE/list
- data/DLA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13602,8 +13602,9 @@ CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, whi
NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/35e3d49d2222c13786a06021c7ed583d2a656e51 (9.18-branch)
NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/833dd3b230b92596074e8da15b12298f46c939f2 (9.18-branch)
CVE-2026-10822 (If BIND encounters a particular invalid data structure in a DNS record ...)
- {DSA-6395-1 DLA-4725-1}
+ {DSA-6395-1}
- bind9 1:9.20.26-1
+ [bookworm] - bind9 1:9.18.49-1~deb12u2
[bullseye] - bind9 <not-affected> (Vulnerable code not present)
NOTE: https://kb.isc.org/docs/cve-2026-10822
NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/d413c9ac2e29a728531354a69c8c8234c01b7d1e (9.18-branch)
=====================================
data/DLA/list
=====================================
@@ -1,5 +1,5 @@
[07 Aug 2026] DLA-4725-1 bind9 - security update
- {CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321}
+ {CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321}
[bullseye] - bind9 1:9.16.50-1~deb11u6
[bookworm] - bind9 1:9.18.49-1~deb12u2
[07 Aug 2026] DLA-4724-1 linux-6.12 - security update
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd290ac19c22a5227031765290956fe06d51ea77
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd290ac19c22a5227031765290956fe06d51ea77
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/a7871eae/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list