On 16 September 2026, Internet Systems Consortium disclosed fourteen 
vulnerabilities affecting our BIND 9 software:

- CVE-2026-19033:       Unauthenticated IXFR deltas are applied to the live 
zone before TSIG verification https://kb.isc.org/docs/cve-2026-19033
- CVE-2026-19662:       qpcache NOQNAME proof use-after-free crashes recursive 
resolver https://kb.isc.org/docs/cve-2026-19662
- CVE-2026-19666:       Use-after-free in query_addnoqnameproof() via the DNS64 
filter64 path https://kb.isc.org/docs/cve-2026-19666
- CVE-2026-19667:       Remote assertion failure via 16-bit length truncation 
in `dns_ncache_add()` https://kb.isc.org/docs/cve-2026-19667
- CVE-2026-19668:       Resource Exhaustion via Excessive DNSSEC Cryptographic 
Material Matching https://kb.isc.org/docs/cve-2026-19668
- CVE-2026-19941:       checkwildcard() accepts an out-of-zone NSEC as a 
wildcard-nonexistence proof https://kb.isc.org/docs/cve-2026-19941
- CVE-2026-75029:       Message parser retains every identical singleton RDATA, 
enabling wire-to-work amplification https://kb.isc.org/docs/cve-2026-75029
- CVE-2026-76163:       named aborts on a TKEY query when the user 
configuration has no global options statement 
https://kb.isc.org/docs/cve-2026-76163
- CVE-2026-77119:       NSEC3 insecure-referral proof can use unrelated cached 
NSEC3 RRsets https://kb.isc.org/docs/cve-2026-77119
- CVE-2026-77692:       Unauthenticated remote crash of named via a single DoH 
SIG(0) request https://kb.isc.org/docs/cve-2026-77692
- CVE-2026-78301:       Out-of-zone database nodes can become authoritative 
zone cuts https://kb.isc.org/docs/cve-2026-78301
- CVE-2026-80274:       Validating resolver can abort while caching a 
mismatched NOQNAME proof https://kb.isc.org/docs/cve-2026-80274
- CVE-2026-81563:       SVCB AliasMode additional-data error leaks qpcache 
references https://kb.isc.org/docs/cve-2026-81563
- CVE-2026-81736:       Remote CPU denial of service through cached SVCB/HTTPS 
AliasMode trees https://kb.isc.org/docs/cve-2026-81736

New versions of BIND 9 are available:

- https://downloads.isc.org/isc/bind9/9.20.29/
- https://downloads.isc.org/isc/bind9/9.21.26/

For more information and other release formats, consult the ISC software 
download page: https://www.isc.org/download/

With the public announcement of these vulnerabilities, the embargo period is 
ended and any updated software packages that have been prepared may be released.

--
Nicki Křížek

Attachment: OpenPGP_0x01623B9B652A20A7.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to