Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:55442: Important: bind9.18 security update

  • What: Security update for bind9.18 in Red Hat Enterprise Linux 9
  • Impact: Systems using BIND may be vulnerable to remote code execution or privilege escalation
Read Full Article →

Red Hat Product Errata RHSA-2026:55442 - Security Advisory Issued: 2026-08-17 Updated: 2026-08-17 RHSA-2026:55442 - Security Advisory Overview Updated Packages Synopsis Important: bind9.18 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for bind9.18 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. Security Fix(es): bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2503721 - CVE-2026-11331 bind9: bind: Potential wildcard CNAME RPZ policy bypass BZ - 2504166 - CVE-2026-13321 bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field BZ - 2504298 - CVE-2026-11622 bind: bind9: Potential memory usage beyond configured limits BZ - 2504338 - CVE-2026-11721 bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards BZ - 2504447 - CVE-2026-13204 bind: bind9: Unexpected exit with NSEC and NSEC3 both present BZ - 2504560 - CVE-2026-10723 bind: bind9: Incorrect acceptance of NSEC3 records CVEs CVE-2026-10723 CVE-2026-11331 CVE-2026-11622 CVE-2026-11721 CVE-2026-13204 CVE-2026-13321 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM bind9.18-9.18.29-14.el9_8.8.src.rpm SHA-256: b72ee4de2d1573aefc8667813b97f560fe318852ed1b8bb6ecd10e523e64303b x86_64 bind9.18-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 22037134327f615b2a171a4e9e65c57171ebca70b082298923c649990865debe bind9.18-chroot-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 6787bc495160263733b01cec621811c34e4dfc71977e59e4f69cc942cb5ecff9 bind9.18-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 3a3b14251e83d7fc6ed73326a4bd68a06b5a6726a55d958208e5f8ab145843d2 bind9.18-debugsource-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 6c208943c1544ba902f23ec04d59181495d1ccfd22cf8477f8a17aa823a73930 bind9.18-dnssec-utils-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 2778b4dbb36738d77d3d671f8c854ed10ff0504023c96274b6cb26a9eceb6a50 bind9.18-dnssec-utils-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: a3ad761172b7909a1bdbd296e963e7e72c3e091bc7f036a69a4ea747bc4afdbf bind9.18-libs-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 99bd0bb8444d07bec2fbf507361028b53a777836651fca15f08cf5f26b9aecc8 bind9.18-libs-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 72008bab18ef5a4d21e6da4c0c13cf3b3b7276ccd9824a64c16fd5bf7affaadc bind9.18-utils-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 55f9c4d872b521d692281511a4174cdfb6c90a0cec77df754fa31d22b4090805 bind9.18-utils-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: c69b5df6d57eca0e5b354f049333133cb1bf806fec91471355790e7c9682dd67 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM bind9.18-9.18.29-14.el9_8.8.src.rpm SHA-256: b72ee4de2d1573aefc8667813b97f560fe318852ed1b8bb6ecd10e523e64303b x86_64 bind9.18-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 22037134327f615b2a171a4e9e65c57171ebca70b082298923c649990865debe bind9.18-chroot-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 6787bc495160263733b01cec621811c34e4dfc71977e59e4f69cc942cb5ecff9 bind9.18-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 3a3b14251e83d7fc6ed73326a4bd68a06b5a6726a55d958208e5f8ab145843d2 bind9.18-debugsource-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 6c208943c1544ba902f23ec04d59181495d1ccfd22cf8477f8a17aa823a73930 bind9.18-dnssec-utils-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 2778b4dbb36738d77d3d671f8c854ed10ff0504023c96274b6cb26a9eceb6a50 bind9.18-dnssec-utils-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: a3ad761172b7909a1bdbd296e963e7e72c3e091bc7f036a69a4ea747bc4afdbf bind9.18-libs-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 99bd0bb8444d07bec2fbf507361028b53a777836651fca15f08cf5f26b9aecc8 bind9.18-libs-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 72008bab18ef5a4d21e6da4c0c13cf3b3b7276ccd9824a64c16fd5bf7affaadc bind9.18-utils-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: 55f9c4d872b521d692281511a4174cdfb6c90a0cec77df754fa31d22b4090805 bind9.18-utils-debuginfo-9.18.29-14.el9_8.8.x86_64.rpm SHA-256: c69b5df6d57eca0e5b354f049333133cb1bf806fec91471355790e7c9682dd67 Red Hat Enterprise Linux for IBM z Systems 9 SRPM bind9.18-9.18.29-14.el9_8.8.src.rpm SHA-256: b72ee4de2d1573aefc8667813b97f560fe318852ed1b8bb6ecd10e523e64303b s390x bind9.18-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 9d7c9cc48126f8a9d97cd7c44539ff07dfa115f650c9f6f8a67c7509f10b3c89 bind9.18-chroot-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 3d5bda0e256e5b88ba837f7f687278b99e3df859be53a52166fb6ce681cc5636 bind9.18-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 88d98d295dc3546de9725d68354ff5bea11b649acf3756a5772791ea50dbe5d0 bind9.18-debugsource-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 9bf2e81a12bbd06a676cc0b18ed6cf522a40842e6a4cc2848b5630800d85415e bind9.18-dnssec-utils-9.18.29-14.el9_8.8.s390x.rpm SHA-256: aad786f4c8c4c545391031dbccae946fe8d6e53dcc0e2095d810d69800b7cc46 bind9.18-dnssec-utils-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: ef7bfde11be38cfe61bc2d21d47e25caeab5d53f80cbabcbceb2fef747421659 bind9.18-libs-9.18.29-14.el9_8.8.s390x.rpm SHA-256: f27199f8befe9adda39260d05c94bdab8a1b172490eaddd2af7519df87f9cfd7 bind9.18-libs-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 160b9ef91d68b3d97e58bca323d41dda397e6b3d2d8d37b6888ecc2ea4f26ed6 bind9.18-utils-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 7758b84e44bbc46687678cbc48d58d49833a4817a055472c07b534fea8c484b0 bind9.18-utils-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 1ff27a26bb7558f17bb84cc04eb4e15fd280fbc6bd8f43c046f2951b7f2e7fca Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM bind9.18-9.18.29-14.el9_8.8.src.rpm SHA-256: b72ee4de2d1573aefc8667813b97f560fe318852ed1b8bb6ecd10e523e64303b s390x bind9.18-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 9d7c9cc48126f8a9d97cd7c44539ff07dfa115f650c9f6f8a67c7509f10b3c89 bind9.18-chroot-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 3d5bda0e256e5b88ba837f7f687278b99e3df859be53a52166fb6ce681cc5636 bind9.18-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 88d98d295dc3546de9725d68354ff5bea11b649acf3756a5772791ea50dbe5d0 bind9.18-debugsource-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 9bf2e81a12bbd06a676cc0b18ed6cf522a40842e6a4cc2848b5630800d85415e bind9.18-dnssec-utils-9.18.29-14.el9_8.8.s390x.rpm SHA-256: aad786f4c8c4c545391031dbccae946fe8d6e53dcc0e2095d810d69800b7cc46 bind9.18-dnssec-utils-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: ef7bfde11be38cfe61bc2d21d47e25caeab5d53f80cbabcbceb2fef747421659 bind9.18-libs-9.18.29-14.el9_8.8.s390x.rpm SHA-256: f27199f8befe9adda39260d05c94bdab8a1b172490eaddd2af7519df87f9cfd7 bind9.18-libs-debuginfo-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 160b9ef91d68b3d97e58bca323d41dda397e6b3d2d8d37b6888ecc2ea4f26ed6 bind9.18-utils-9.18.29-14.el9_8.8.s390x.rpm SHA-256: 7758b84e44bbc46687678cbc48d58d49833a4817a055472c07b534fea8c484b0 bind9.18-utils-debuginfo-9.18.29-14.el9_8

Share this article