[Git][security-tracker-team/security-tracker][master] new bind9 issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 16 18:35:08 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
92d31263 by Moritz Muehlenhoff at 2026-09-16T19:34:48+02:00
new bind9 issues
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,45 @@
+CVE-2026-19033 [Unauthenticated IXFR deltas are applied to the live zone before TSIG verification]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-19033
+CVE-2026-19662 [qpcache NOQNAME proof use-after-free crashes recursive resolver]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-19662
+CVE-2026-19666 [Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-19666
+CVE-2026-19667 [Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-19667
+CVE-2026-19668 [Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-19668
+CVE-2026-19941 [checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-19941
+CVE-2026-75029 [Message parser retains every identical singleton RDATA, enabling wire-to-work amplification]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-75029
+CVE-2026-76163 [named aborts on a TKEY query when the user configuration has no global options statement]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-76163
+CVE-2026-77119 [NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-77119
+CVE-2026-77692 [Unauthenticated remote crash of named via a single DoH SIG(0) request]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-77692
+CVE-2026-78301 [Out-of-zone database nodes can become authoritative zone cuts]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-78301
+CVE-2026-80274 [Validating resolver can abort while caching a mismatched NOQNAME proof]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-80274
+CVE-2026-81563 [SVCB AliasMode additional-data error leaks qpcache references]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-81563
+CVE-2026-81736 [Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees]
+ - bind9 1:9.20.29-1
+ NOTE: https://kb.isc.org/docs/cve-2026-81736
CVE-2026-81642
- unbound 1.26.1-1
NOTE: https://nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt
=====================================
data/dsa-needed.txt
=====================================
@@ -20,6 +20,8 @@ activemq
amd64-microcode (carnil)
Coordinating with maintainer DSA/bookworm-pu and sync with mitgations in src:linux
--
+bind9
+--
bouncycastle
possibly move to 1.85 for trixie
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/92d312631c69a8b94c6360430df7f9fae8c4f192
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/92d312631c69a8b94c6360430df7f9fae8c4f192
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/270b7021/attachment.htm>
More information about the debian-security-tracker-commits
mailing list