bind9.16-9.16.23-0.22.el8_10.12
エラータID: AXSA:2026-1555:03
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
* bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
* bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622)
* bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
* bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
* bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11331
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11622
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11721
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-13321
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Update packages.
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
N/A
SRPMS
- bind9.16-9.16.23-0.22.el8_10.12.src.rpm
MD5: 170e64f758a46eeaf5b114217d3013ed
SHA-256: 4c0a6fce48d6aa3984689766929a99fd2a12fade4d271f9bfab1092717d604ac
Size: 5.20 MB
Asianux Server 8 for x86_64
- bind9.16-9.16.23-0.22.el8_10.12.x86_64.rpm
MD5: c309962344ed3d70ed58e9160bb51457
SHA-256: f26c9352a83f5a6ab1ff03d8d7ae31d475459b656853726b3d1006c4218a4967
Size: 606.12 kB - bind9.16-chroot-9.16.23-0.22.el8_10.12.x86_64.rpm
MD5: 9c92e46cd1ceced5b17eb0df5c6bced6
SHA-256: 2a2bd4242e1768ec53f131c0bcd16b3a1136915834d893e701b17ff48f183042
Size: 113.87 kB - bind9.16-devel-9.16.23-0.22.el8_10.12.i686.rpm
MD5: 22076b6bdaa198223bfc4b731311d1fa
SHA-256: d80adbbf55ef61ad6cf01aa457f145fd0e88f1b6d64be82cfecb1fe516f89c12
Size: 430.05 kB - bind9.16-devel-9.16.23-0.22.el8_10.12.x86_64.rpm
MD5: 23f55330b9630525b99a99a4e44f018f
SHA-256: 4f6132ee138f62b5ec4d09056271799d2970d3c4e2aaff61bbc93909333b1b69
Size: 430.02 kB - bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.x86_64.rpm
MD5: 67e7815a1ceae91e7e0d7ddb1201a8e7
SHA-256: 053b5b77bce7514ec1e44de85d7a2935fd827eeb84e7b7ac9d0273b283e379ef
Size: 247.17 kB - bind9.16-doc-9.16.23-0.22.el8_10.12.noarch.rpm
MD5: 928d2631cb73bceb88fe92dc7485f3ab
SHA-256: c8e0de2f31832ce6718b02cf1dbe93896c9a81a7bb1aa52800536a12fcd66b13
Size: 3.67 MB - bind9.16-libs-9.16.23-0.22.el8_10.12.i686.rpm
MD5: fea14e4793c5a1ca5ddb772d68a6dccc
SHA-256: f62cf6b32acad937fc105f28817a1ec7dc177e2acec1018c7a16a53dd32a2182
Size: 1.46 MB - bind9.16-libs-9.16.23-0.22.el8_10.12.x86_64.rpm
MD5: bbc6062f5bc80c24f72e0ab067bf05ee
SHA-256: a2e965a144138b4905187e5d53b4cf99a6aae8924e2bdb1ceed8b1b3f23047b8
Size: 1.36 MB - bind9.16-license-9.16.23-0.22.el8_10.12.noarch.rpm
MD5: ffa0cdc2c1974cb079956d5f8755068d
SHA-256: 393db10192a098f041ba8507e859ab1b2af2ca80a3f96c60d6030af15f49896d
Size: 110.10 kB - bind9.16-utils-9.16.23-0.22.el8_10.12.x86_64.rpm
MD5: 0a221e11f32b023d3dec8a78250d345e
SHA-256: 8f848f991e232c2779136f5895c695efc6b7672999bcd1c1b1178174b9a89d50
Size: 292.20 kB - python3-bind9.16-9.16.23-0.22.el8_10.12.noarch.rpm
MD5: f0364d8c9856fb0a84c525afe8159cbb
SHA-256: 607c7a86a74d2c812fb993a2e51471f6d065234aa93dc26b03fb6549d45d4c37
Size: 158.39 kB