bind9.18-9.18.29-14.el9_8.8

エラータID: AXSA:2026-1671:05

Release date: 
Thursday, August 27, 2026 - 11:53
Subject: 
bind9.18-9.18.29-14.el9_8.8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.

Security Fix(es):

* bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
* bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
* bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622)
* bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
* bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
* bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11331
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11622
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11721
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-13321
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. bind9.18-9.18.29-14.el9_8.8.src.rpm
    MD5: 3da8e42557615297d0d2403d54ab8a87
    SHA-256: 96a3cb831d71a984d159f0664d21c688f4cbf9cf97d1c8253ff6d577e1983c87
    Size: 5.50 MB

Asianux Server 9 for x86_64
  1. bind9.18-9.18.29-14.el9_8.8.x86_64.rpm
    MD5: 8f9c74b6c832de34611aab7699b7bfbe
    SHA-256: 9be252979bcdc4b24cac07f03bb11ad58d66bfd126da4a4f843a71fec30ac192
    Size: 531.73 kB
  2. bind9.18-chroot-9.18.29-14.el9_8.8.x86_64.rpm
    MD5: 2d1d0da6ee4b376bce9e26be89f824a7
    SHA-256: 5469f7698a978088158f8059e7513f1ae6198b23eda177cbff78f2606a8b91d0
    Size: 17.35 kB
  3. bind9.18-devel-9.18.29-14.el9_8.8.i686.rpm
    MD5: 0435a5fa44139d4dca446691873af7aa
    SHA-256: 37a5614e76b94a4be60a698b89c397101753d93fff0d3f177f4f71f9bed90fc1
    Size: 339.03 kB
  4. bind9.18-devel-9.18.29-14.el9_8.8.x86_64.rpm
    MD5: 8312d9ba81a6084b2a16446d488af746
    SHA-256: 1dad75535bfe96b44db0f873602ec4855d8eb9e5eb9d1e39754613643399b3f8
    Size: 339.03 kB
  5. bind9.18-dnssec-utils-9.18.29-14.el9_8.8.x86_64.rpm
    MD5: 10f0ad486dc78a59b89085d37b50d7dc
    SHA-256: fdd5272184c3d4e187782930131bf028ca2c16c9946383e196750200aa6a5b57
    Size: 148.71 kB
  6. bind9.18-doc-9.18.29-14.el9_8.8.noarch.rpm
    MD5: 8d852697d793545e198610ac3066af5f
    SHA-256: 59fef3e2c07839c5c9d56fc649348753f2e0c7979ebe210a66d33fe96f782f94
    Size: 2.70 MB
  7. bind9.18-libs-9.18.29-14.el9_8.8.i686.rpm
    MD5: 373f60fa8dc821b78797a7bd9bdc73f0
    SHA-256: 116e705ae91e2a1d2db3630fd7a9f9f94d0ac6cfc0e14715887d123e4cba1538
    Size: 1.34 MB
  8. bind9.18-libs-9.18.29-14.el9_8.8.x86_64.rpm
    MD5: 305d9d56398dcd4ca09827bdbc3c6a80
    SHA-256: ca4e3ebb5a86866f94bd06f1d7af5a58ce260706b1984b12b064ed53e6247cc4
    Size: 1.26 MB
  9. bind9.18-utils-9.18.29-14.el9_8.8.x86_64.rpm
    MD5: 93663a45da26daa244134e89e86d10c4
    SHA-256: 067fe115c7d6aa1093426ab312c971c9393cb444992eaab8783898cfa3b626ed
    Size: 222.28 kB