bind9.16-9.16.23-0.22.el8_10.6
エラータID: AXSA:2026-763:02
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039)
* bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-3039
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
CVE-2026-5946
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
Update packages.
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
N/A
SRPMS
- bind9.16-9.16.23-0.22.el8_10.6.src.rpm
MD5: 46ce4cab83ccb04bc24d93b248bfd856
SHA-256: 7d8f45e7608ffbd80f123e022b9bcef0acc0de69bfe3d1badc2456545074c775
Size: 5.18 MB
Asianux Server 8 for x86_64
- bind9.16-9.16.23-0.22.el8_10.6.x86_64.rpm
MD5: 6d00d4db6ee68bd86b52b0770f8dd1ab
SHA-256: 307a69e3b896ddb70775d6c0a319847a204d613a8366581f1e286d8bc73d7da3
Size: 605.13 kB - bind9.16-chroot-9.16.23-0.22.el8_10.6.x86_64.rpm
MD5: 9c34f5592e7456b87471144aaad33ac1
SHA-256: ded60f466592b64f2ff5bb1180120508e563e5bb620bb66b1a9bdfe76fdc6ff0
Size: 112.87 kB - bind9.16-devel-9.16.23-0.22.el8_10.6.i686.rpm
MD5: ff43ee5edef98c39e45e5daaeab39831
SHA-256: 9c5a1ce6e524e9c81f9ba43555762de61f06f60b8439d541bbca90d24e753897
Size: 429.00 kB - bind9.16-devel-9.16.23-0.22.el8_10.6.x86_64.rpm
MD5: b8097c5b098e64580dcfd5a06c7624e5
SHA-256: de67f65f7dc8e0a97b087dbbf8be1a77f9ba95082f60cc4fffcbbc24433396c7
Size: 428.95 kB - bind9.16-dnssec-utils-9.16.23-0.22.el8_10.6.x86_64.rpm
MD5: f54b01c1ada693d37ff7f49adb5a56dc
SHA-256: 143d58d121692c34466032e62bb0e1db1b41fa2c5c1077070e649b8478142580
Size: 246.09 kB - bind9.16-doc-9.16.23-0.22.el8_10.6.noarch.rpm
MD5: d6157fa6e2cf6af6adb0c114cccdb8b2
SHA-256: f28770f64464ee406aefb8a8a4a895d699f0de70e7b10ee92c9b5b80da012320
Size: 3.67 MB - bind9.16-libs-9.16.23-0.22.el8_10.6.i686.rpm
MD5: 450d9721057fff21dda16ff319938233
SHA-256: 55c34614737d3db79881306adb64c469a391d8c066b55b4f7f7ff4cf985aa541
Size: 1.46 MB - bind9.16-libs-9.16.23-0.22.el8_10.6.x86_64.rpm
MD5: 039692ca2f0e712c18c5debe0bafcc17
SHA-256: ef91861ce7f36d9c4f9c505c67b7b5366746724940e37cacd23b7b021e32eef7
Size: 1.36 MB - bind9.16-license-9.16.23-0.22.el8_10.6.noarch.rpm
MD5: 5b3e23baddd644b1c8a7dfacca5e4646
SHA-256: 29b4f0aefcc81a2347c954b76e3b06fc72d84b7df53654d777db8af2ad365ff3
Size: 109.11 kB - bind9.16-utils-9.16.23-0.22.el8_10.6.x86_64.rpm
MD5: c13023d79b01c625279b8913f3406c08
SHA-256: 0fd217211b702803b734d4861576fe7d3b0aa4e87210ac5212d31b4ca6a75b14
Size: 291.20 kB - python3-bind9.16-9.16.23-0.22.el8_10.6.noarch.rpm
MD5: a78a378ffed9d6d30b4dd9fb1fe4cce1
SHA-256: 803ee553b25bb2fb9857bb437a4ed87789373881fc0881592d82cf18992918b1
Size: 157.41 kB