Red Hat Product Errata RHSA-2026:24338 - Security Advisory Issued: 2026-06-08 Updated: 2026-06-08 RHSA-2026:24338 - Security Advisory Overview Updated Packages Synopsis Important: bind security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for bind is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2479767 - CVE-2026-3039 bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation BZ - 2479771 - CVE-2026-5946 bind: BIND: Denial of Service via specially crafted DNS messages CVEs CVE-2026-3039 CVE-2026-5946 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM bind-9.18.33-15.el10_2.2.src.rpm SHA-256: eb38f96d97c2c8fc8e41cafd0fc59dd30722f3f586be7dbe92f17b45095d3f2e x86_64 bind-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 9a8786cf027bcdf593cb368961bd0156ef6379143bf9cd1866054cbedb401a5d bind-chroot-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: b68cd77f6fd7a3c01133af105124d061271767acce8e73d7ec5850159038d808 bind-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: e6e0fe5176cea03a773b54c8eab8eac3d82d7071171ed34220bf14e250a5d752 bind-debugsource-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: ffdf27952dbceff69425864f36117742d4e50607bd73821c716a8dbb4cf44177 bind-dnssec-utils-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: e84aad869c968411feb9b2244767cd2759fc034dee647ece7d51d73a9f11e9bd bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: e7a03af594da0545232e5d7f9195827a4e9a841d3782d25356224597b42a953e bind-libs-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 6cfe6df335c646a59b2b12870d9ad803f1d97b245e0a4a80703a1415e60b45ed bind-libs-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 444946695bb6f36ff438baed87f1c4e1ed3fedd04afd6feaf60d2ade7fa6801c bind-license-9.18.33-15.el10_2.2.noarch.rpm SHA-256: 098320190e2cfaea17c0e7b9915aa8cf6c6bc2f28e329ebc8091c6fc4eac0a19 bind-utils-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: c5a3c3489a99b612130d57250789cfd741653fd29d8b4f014fcdaf4a762d3ed2 bind-utils-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 66cb03970350931335ec3b797e0d824680e2e445ddd3c93adf9404bde618b123 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM bind-9.18.33-15.el10_2.2.src.rpm SHA-256: eb38f96d97c2c8fc8e41cafd0fc59dd30722f3f586be7dbe92f17b45095d3f2e x86_64 bind-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 9a8786cf027bcdf593cb368961bd0156ef6379143bf9cd1866054cbedb401a5d bind-chroot-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: b68cd77f6fd7a3c01133af105124d061271767acce8e73d7ec5850159038d808 bind-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: e6e0fe5176cea03a773b54c8eab8eac3d82d7071171ed34220bf14e250a5d752 bind-debugsource-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: ffdf27952dbceff69425864f36117742d4e50607bd73821c716a8dbb4cf44177 bind-dnssec-utils-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: e84aad869c968411feb9b2244767cd2759fc034dee647ece7d51d73a9f11e9bd bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: e7a03af594da0545232e5d7f9195827a4e9a841d3782d25356224597b42a953e bind-libs-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 6cfe6df335c646a59b2b12870d9ad803f1d97b245e0a4a80703a1415e60b45ed bind-libs-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 444946695bb6f36ff438baed87f1c4e1ed3fedd04afd6feaf60d2ade7fa6801c bind-license-9.18.33-15.el10_2.2.noarch.rpm SHA-256: 098320190e2cfaea17c0e7b9915aa8cf6c6bc2f28e329ebc8091c6fc4eac0a19 bind-utils-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: c5a3c3489a99b612130d57250789cfd741653fd29d8b4f014fcdaf4a762d3ed2 bind-utils-debuginfo-9.18.33-15.el10_2.2.x86_64.rpm SHA-256: 66cb03970350931335ec3b797e0d824680e2e445ddd3c93adf9404bde618b123 Red Hat Enterprise Linux for IBM z Systems 10 SRPM bind-9.18.33-15.el10_2.2.src.rpm SHA-256: eb38f96d97c2c8fc8e41cafd0fc59dd30722f3f586be7dbe92f17b45095d3f2e s390x bind-9.18.33-15.el10_2.2.s390x.rpm SHA-256: c05e72ad0a9bef5b96299fc15b881b664bc55ae3d5ac14885a5e8488e95634cf bind-chroot-9.18.33-15.el10_2.2.s390x.rpm SHA-256: c5dc1a7d10894b278d39875d31d8d92f7ae0a1d0b788bf8a224840715cb91f8b bind-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 7b9e36debe750b64dd0cd9d18a897cd805d578df12aacd340cab306283e406ac bind-debugsource-9.18.33-15.el10_2.2.s390x.rpm SHA-256: f3e578e1d37067ea660daadcbe8c59562ad201785ffccc107538c62fb1531299 bind-dnssec-utils-9.18.33-15.el10_2.2.s390x.rpm SHA-256: ea0d0088fcc95ff4d36c5a454a1f8f8d0c761e56706cacefdadeac63b8da9faa bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 7ff1cda783f59895de0f8f4cae1c7354964a6345814d666414e6ce5af14c7765 bind-libs-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 36cf37a49e3d9f8b73d1784d15ab9d51d5def82e9c1314e88f5a4ee7768c939f bind-libs-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: a00f18d0adccdff7f9bb6a47cc4d12cb3dc6649157103dff02bac0fcf946b1f4 bind-license-9.18.33-15.el10_2.2.noarch.rpm SHA-256: 098320190e2cfaea17c0e7b9915aa8cf6c6bc2f28e329ebc8091c6fc4eac0a19 bind-utils-9.18.33-15.el10_2.2.s390x.rpm SHA-256: a4e392a906a31f8e1b536677df930c8ac17495b10772c0092919be70aec6a297 bind-utils-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 4153561cd1becde80b08b774a07c92a0311dc3f5a63e15c474a22e83f849da3b Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM bind-9.18.33-15.el10_2.2.src.rpm SHA-256: eb38f96d97c2c8fc8e41cafd0fc59dd30722f3f586be7dbe92f17b45095d3f2e s390x bind-9.18.33-15.el10_2.2.s390x.rpm SHA-256: c05e72ad0a9bef5b96299fc15b881b664bc55ae3d5ac14885a5e8488e95634cf bind-chroot-9.18.33-15.el10_2.2.s390x.rpm SHA-256: c5dc1a7d10894b278d39875d31d8d92f7ae0a1d0b788bf8a224840715cb91f8b bind-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 7b9e36debe750b64dd0cd9d18a897cd805d578df12aacd340cab306283e406ac bind-debugsource-9.18.33-15.el10_2.2.s390x.rpm SHA-256: f3e578e1d37067ea660daadcbe8c59562ad201785ffccc107538c62fb1531299 bind-dnssec-utils-9.18.33-15.el10_2.2.s390x.rpm SHA-256: ea0d0088fcc95ff4d36c5a454a1f8f8d0c761e56706cacefdadeac63b8da9faa bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 7ff1cda783f59895de0f8f4cae1c7354964a6345814d666414e6ce5af14c7765 bind-libs-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 36cf37a49e3d9f8b73d1784d15ab9d51d5def82e9c1314e88f5a4ee7768c939f bind-libs-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: a00f18d0adccdff7f9bb6a47cc4d12cb3dc6649157103dff02bac0fcf946b1f4 bind-license-9.18.33-15.el10_2.2.noarch.rpm SHA-256: 098320190e2cfaea17c0e7b9915aa8cf6c6bc2f28e329ebc8091c6fc4eac0a19 bind-utils-9.18.33-15.el10_2.2.s390x.rpm SHA-256: a4e392a906a31f8e1b536677df930c8ac17495b10772c0092919be70aec6a297 bind-utils-debuginfo-9.18.33-15.el10_2.2.s390x.rpm SHA-256: 4153561cd1becde80b08b774a07c92a0311dc3f5a63e15c474a22e83f849da3b Red Hat Enterprise Linux for Power, little endian 10 SRPM bind-9.18.33-15.el10_2.2.src.rpm SHA-256: eb38f96d97c2c8fc8e41cafd0fc59dd30722f3f586be7dbe92f17b45095d3f2e ppc64le bind-9.18.33-15.el10_2.2.ppc64le.rpm SHA-256: 30f9e21c92cb986c535c88d3faa24bd7bbe5e665bb23fedab4a2f42006e9b9da bind-chroot-9.18.33-15.el10_2.2.ppc64le.rpm SHA-256: 4a56871d8a57
This Important Red Hat security update addresses two high-severity vulnerabilities (CVE-2026-3039 and CVE-2026-5946, both CVSS 7.5) in BIND 9: a memory exhaustion flaw during GSS-API TKEY negotiation and a denial-of-service vulnerability triggered by specially crafted DNS messages. The affected versions are BIND 9.0.0 through 9.16.50, 9.18.0 through <9.18.49, 9.20.0 through <9.20.23, and 9.21.0 through <9.21.22. The fixed versions are BIND 9.18.49, 9.20.23, and 9.21.22.