bind-9.16.23-40.el9_8.8
エラータID: AXSA:2026-1632:09
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.
Security Fix(es):
* bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
* bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
* bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622)
* bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
* bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
* bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11331
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11622
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-11721
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-13321
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Update packages.
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
N/A
SRPMS
- bind-9.16.23-40.el9_8.8.src.rpm
MD5: 09b8a5a168c58343add668fe16b43820
SHA-256: 6e0b574f61937585a97645fdd751a5db65d3823dc29796776e50e74a3c23678c
Size: 5.14 MB
Asianux Server 9 for x86_64
- bind-9.16.23-40.el9_8.8.x86_64.rpm
MD5: 84519e1c633a29237fc8f6a74dd62c3e
SHA-256: 848c73f62cedf798c2a432e5c333e685ce6420e1b6b059e3ae13a447d1f94a74
Size: 502.37 kB - bind-chroot-9.16.23-40.el9_8.8.x86_64.rpm
MD5: ef1b051f5bd5c667bfe3943c85aef034
SHA-256: dae3e272a6a7d0e9ba3a40355068336359aaf104346152723b491cf7488ede0b
Size: 17.36 kB - bind-devel-9.16.23-40.el9_8.8.i686.rpm
MD5: 4e2cbfcefc49f1c9fa2f85966c5203ea
SHA-256: 0a173674751b9118f77daa29744f7eacffa4bbd4c5b99a018a7b65dddbc08f4e
Size: 360.27 kB - bind-devel-9.16.23-40.el9_8.8.x86_64.rpm
MD5: 8690b78bdb500ba541a0162cf8e69b03
SHA-256: 6c404642118dbdb84eec6924f15665791ee98c1e9dec743e5db51abfbe74dcaa
Size: 360.22 kB - bind-dnssec-doc-9.16.23-40.el9_8.8.noarch.rpm
MD5: 1e223f07436bf9bef3bb1a224898a327
SHA-256: e1f12ad6dd61f5cf130793fd9a900c47ce9c5397f72798e8099cf312d6c92ff9
Size: 45.36 kB - bind-dnssec-utils-9.16.23-40.el9_8.8.x86_64.rpm
MD5: 8721b845b39d0af70929dd8f35913908
SHA-256: e08890eaf040a78333b7ed8edf5ea0adb5568e90960315fa7a661d46d7344b9f
Size: 112.78 kB - bind-doc-9.16.23-40.el9_8.8.noarch.rpm
MD5: 2e0baee40daae64274e46795bc05f872
SHA-256: bad5120bf4fab245c1b5883498784e9ca859d92c5080ef181181de5cf6023017
Size: 2.09 MB - bind-libs-9.16.23-40.el9_8.8.i686.rpm
MD5: e8144022d574903510cced692fd75960
SHA-256: c607f141e8fb8fe5913bde26dd43612cf9633bb1c3e3ba05daa87f87e571662c
Size: 1.34 MB - bind-libs-9.16.23-40.el9_8.8.x86_64.rpm
MD5: 18ecafe2d313c4ea8ccbb605f17e446a
SHA-256: 1f9f9d2f76ae586d7c0105e368f5efea6ae0aebef617a81cc289255ace1b9227
Size: 1.24 MB - bind-license-9.16.23-40.el9_8.8.noarch.rpm
MD5: ed7d4cd09537f490fcbc612f57a436e0
SHA-256: b44e3d9a669d4680e2b96a71d8d5eff9ca8e311443854f1aadc5cbc130f607aa
Size: 12.89 kB - bind-utils-9.16.23-40.el9_8.8.x86_64.rpm
MD5: a50046a87cd99365a67ca51b87abf41d
SHA-256: 5f18d774c58f075007a87ef3b887c3975b329fa67e843f4e201627475becf0a4
Size: 205.55 kB - python3-bind-9.16.23-40.el9_8.8.noarch.rpm
MD5: 5b346e15f20584df981370d0dc4af6a5
SHA-256: 1569f9a5ab756ad286c9dd5bd35453f58670d7ca6f830a5d730873583e516a06
Size: 71.61 kB