Red Hat Product Errata RHSA-2026:55437 - Security Advisory Issued: 2026-08-17 Updated: 2026-08-17 RHSA-2026:55437 - Security Advisory Overview Updated Packages Synopsis Important: bind security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for bind is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2503721 - CVE-2026-11331 bind9: bind: Potential wildcard CNAME RPZ policy bypass BZ - 2504166 - CVE-2026-13321 bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field BZ - 2504298 - CVE-2026-11622 bind: bind9: Potential memory usage beyond configured limits BZ - 2504338 - CVE-2026-11721 bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards BZ - 2504447 - CVE-2026-13204 bind: bind9: Unexpected exit with NSEC and NSEC3 both present BZ - 2504560 - CVE-2026-10723 bind: bind9: Incorrect acceptance of NSEC3 records CVEs CVE-2026-10723 CVE-2026-11331 CVE-2026-11622 CVE-2026-11721 CVE-2026-13204 CVE-2026-13321 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM bind-9.18.33-15.el10_2.10.src.rpm SHA-256: 0d9e704bc4b14a7d959289f2751c78df29cff148920adf7042a6eda00d807c6f x86_64 bind-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: f7e7efba27ff7a86a19bb59161f61ceed4a771c122e589fd2ddcc2a04e4cdba0 bind-chroot-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 05945ad47be6a6f6f82982ab91687203f218534be7d6554a654b52c2db007a5a bind-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: e5d02c45f45e740c40afd17e9a8a4ebcf09106d758d57bf791a1f7707f6c7130 bind-debugsource-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 0e6390047df27acc6418f6bce8b66a367be46df8f7cefe52a58047aca4a0f270 bind-dnssec-utils-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 0dec398da1b0b204881a8c74c7133c57b978c43f65493a030d8472f43b8d867a bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 541b6cc8b3cadc7817d759d8c00f2ec4a59773fcee3e5d6c45ec2def201ee36f bind-libs-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 84221861f077c6ec8de715a3707d5105b76e89bb35bcb315fea281a6d2a7fcce bind-libs-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 74de35de0037447bf3c25666594d0a2956510e65bde90d6d5851b52961942afe bind-license-9.18.33-15.el10_2.10.noarch.rpm SHA-256: cd95b5d3c96a4818e59cd205ad937857ce8c7666e8d24b1ffd8203c1ee8095e7 bind-utils-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: fb85a17c4beda45c6fcbb841c36c352747c6bb3d9ad30fbba358c1a791ac2e06 bind-utils-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 5590fdb616881e4e074119124e7ccd206264c52703209278d194f19c44dfb490 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM bind-9.18.33-15.el10_2.10.src.rpm SHA-256: 0d9e704bc4b14a7d959289f2751c78df29cff148920adf7042a6eda00d807c6f x86_64 bind-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: f7e7efba27ff7a86a19bb59161f61ceed4a771c122e589fd2ddcc2a04e4cdba0 bind-chroot-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 05945ad47be6a6f6f82982ab91687203f218534be7d6554a654b52c2db007a5a bind-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: e5d02c45f45e740c40afd17e9a8a4ebcf09106d758d57bf791a1f7707f6c7130 bind-debugsource-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 0e6390047df27acc6418f6bce8b66a367be46df8f7cefe52a58047aca4a0f270 bind-dnssec-utils-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 0dec398da1b0b204881a8c74c7133c57b978c43f65493a030d8472f43b8d867a bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 541b6cc8b3cadc7817d759d8c00f2ec4a59773fcee3e5d6c45ec2def201ee36f bind-libs-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 84221861f077c6ec8de715a3707d5105b76e89bb35bcb315fea281a6d2a7fcce bind-libs-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 74de35de0037447bf3c25666594d0a2956510e65bde90d6d5851b52961942afe bind-license-9.18.33-15.el10_2.10.noarch.rpm SHA-256: cd95b5d3c96a4818e59cd205ad937857ce8c7666e8d24b1ffd8203c1ee8095e7 bind-utils-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: fb85a17c4beda45c6fcbb841c36c352747c6bb3d9ad30fbba358c1a791ac2e06 bind-utils-debuginfo-9.18.33-15.el10_2.10.x86_64.rpm SHA-256: 5590fdb616881e4e074119124e7ccd206264c52703209278d194f19c44dfb490 Red Hat Enterprise Linux for IBM z Systems 10 SRPM bind-9.18.33-15.el10_2.10.src.rpm SHA-256: 0d9e704bc4b14a7d959289f2751c78df29cff148920adf7042a6eda00d807c6f s390x bind-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 19c5380117fc7946d33efbb71208da15e7adfd170a72bcc0aa5b010d03895d04 bind-chroot-9.18.33-15.el10_2.10.s390x.rpm SHA-256: d6f6f0ed14b271c8abbfcf73017fa44762dc09b70f07990249b3d6c4979c7693 bind-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 15750faee1042f1e8908a56d6de8250da5f6571e56aee75f8f37d1cd83dff718 bind-debugsource-9.18.33-15.el10_2.10.s390x.rpm SHA-256: a38c6c1521e9b30575f04d04e9a2279143ed7b686ad6155a85e151ed80b0360e bind-dnssec-utils-9.18.33-15.el10_2.10.s390x.rpm SHA-256: ac77d5d69871be47abe6a2ea78209f627ac9d1fbb96af14de6a5fd4878d18b8b bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 9430317fc8c8be33e7818a860d3e1cc9259a37e4470c81a718f20476c175a802 bind-libs-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 65ba46d5103e175e37c3b78f225a0db15f81de608d8dfb1042b41c18765d9fbc bind-libs-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SHA-256: d3503171c1585f482bb6f9949987f280edcbfb59bae5e15601118a0234fc3160 bind-license-9.18.33-15.el10_2.10.noarch.rpm SHA-256: cd95b5d3c96a4818e59cd205ad937857ce8c7666e8d24b1ffd8203c1ee8095e7 bind-utils-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 3f2155c7e4f2b8004155ee6aa50daece740ce02f19448aedd99cd921641ec761 bind-utils-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 14f226f21a26198e55760b94bb88731850f859693d462f455144d55621939387 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM bind-9.18.33-15.el10_2.10.src.rpm SHA-256: 0d9e704bc4b14a7d959289f2751c78df29cff148920adf7042a6eda00d807c6f s390x bind-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 19c5380117fc7946d33efbb71208da15e7adfd170a72bcc0aa5b010d03895d04 bind-chroot-9.18.33-15.el10_2.10.s390x.rpm SHA-256: d6f6f0ed14b271c8abbfcf73017fa44762dc09b70f07990249b3d6c4979c7693 bind-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 15750faee1042f1e8908a56d6de8250da5f6571e56aee75f8f37d1cd83dff718 bind-debugsource-9.18.33-15.el10_2.10.s390x.rpm SHA-256: a38c6c1521e9b30575f04d04e9a2279143ed7b686ad6155a85e151ed80b0360e bind-dnssec-utils-9.18.33-15.el10_2.10.s390x.rpm SHA-256: ac77d5d69871be47abe6a2ea78209f627ac9d1fbb96af14de6a5fd4878d18b8b bind-dnssec-utils-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 9430317fc8c8be33e7818a860d3e1cc9259a37e4470c81a718f20476c175a802 bind-libs-9.18.33-15.el10_2.10.s390x.rpm SHA-256: 65ba46d5103e175e37c3b78f225a0db15f81de608d8dfb1042b41c18765d9fbc bind-libs-debuginfo-9.18.33-15.el10_2.10.s390x.rpm SH
This Red Hat security advisory addresses multiple high-severity vulnerabilities (CVSS up to 8.6) in BIND, including a DNSSEC validation bypass, cache poisoning vectors, and a policy bypass. The update applies to Red Hat Enterprise Linux 10 and its Extended Update Support variants. Administrators should apply the referenced Red Hat update to affected systems to mitigate these risks.