[Git][security-tracker-team/security-tracker][master] Track fixed verson for bind9 issues via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 24 06:13:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b0cbe32b by Salvatore Bonaccorso at 2026-07-24T07:13:19+02:00
Track fixed verson for bind9 issues via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1072,39 +1072,39 @@ CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'vie
NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, which cou ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-10723
CVE-2026-10822 (If BIND encounters a particular invalid data structure in a DNS record ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-10822
CVE-2026-11331 (An attacker who knows (or guesses) that a resolver uses RPZ with wildc ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-11331
CVE-2026-11605 (The issue is a resource exhaustion vulnerability associated with DNSSE ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-11605
CVE-2026-11622 (A DNSSEC validating resolver that is under a random subdomain attack a ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-11622
CVE-2026-11721 (It is possible for an attacker's zone to respond to a query with an RR ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-11721
CVE-2026-12617 (The issue is unexpected program termination based on ordering and/or s ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-12617
CVE-2026-13204 (If a provably insecure domain is covered by both an NSEC and NSEC3 rec ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-13204
CVE-2026-13321 (The BIND resolver accepts validly-signed NSEC records where the "Next ...)
{DSA-6395-1}
- - bind9 <unfixed>
+ - bind9 1:9.20.26-1
NOTE: https://kb.isc.org/docs/cve-2026-13321
CVE-2026-52688 (RRSIGs with too few labels can lead to bypass of DNSSEC wildcard valid ...)
{DSA-6397-1}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0cbe32ba2de1de4321ec0142fdc9bcbf43842b2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b0cbe32ba2de1de4321ec0142fdc9bcbf43842b2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/38cb7451/attachment.htm>
More information about the debian-security-tracker-commits
mailing list