Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:57189: Important: bind security update

This Red Hat advisory addresses multiple Important-severity vulnerabilities in BIND 9, including a memory exhaustion flaw during GSS-API TKEY negotiation (CVE-2026-3039, CVSS 7.5) and a Denial of Service via crafted DNS messages (CVE-2026-5946, CVSS 7.5). Affected versions include BIND 9.18.0 to 9.18.48, 9.20.0 to 9.20.22, and 9.21.0 to 9.21.21, with fixes provided in versions 9.18.49, 9.20.23, and 9.21.22 respectively. The update also resolves several other security flaws, including cache poisoning and DNSSEC validation bypass issues.
Read Full Article →

Red Hat Product Errata RHSA-2026:57189 - Security Advisory Issued: 2026-08-19 Updated: 2026-08-19 RHSA-2026:57189 - Security Advisory Overview Updated Packages Synopsis Important: bind security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for bind is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946) bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2479767 - CVE-2026-3039 bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation BZ - 2479771 - CVE-2026-5946 bind: BIND: Denial of Service via specially crafted DNS messages BZ - 2503721 - CVE-2026-11331 bind9: bind: Potential wildcard CNAME RPZ policy bypass BZ - 2504166 - CVE-2026-13321 bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field BZ - 2504298 - CVE-2026-11622 bind: bind9: Potential memory usage beyond configured limits BZ - 2504338 - CVE-2026-11721 bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards BZ - 2504447 - CVE-2026-13204 bind: bind9: Unexpected exit with NSEC and NSEC3 both present BZ - 2504560 - CVE-2026-10723 bind: bind9: Incorrect acceptance of NSEC3 records CVEs CVE-2026-3039 CVE-2026-5946 CVE-2026-10723 CVE-2026-11331 CVE-2026-11622 CVE-2026-11721 CVE-2026-13204 CVE-2026-13321 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM bind-9.16.23-18.el9_4.12.src.rpm SHA-256: f6c9c58fe29753fe89099af70aae6dba0d1e9f9bc372df3bfe5c157d257dcfdf x86_64 bind-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: d979d43dc308728a56b0df1d1fadad699966e79ed6a0f7a2ce65e46bb8db19e6 bind-chroot-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 102a5db9aabe91e209f79fcf53aec4e743d9240f8c8dc0c2ed3efb6214801d3b bind-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 571a2b8e2ed9fdf69a6279d635e9d33057a5dd004980eb2f44add600e7340885 bind-debugsource-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 51ef8bd6e7cec7ff96e5ea139b40fc244ce2060d5c446df3fbe47e9c4bb3df11 bind-dnssec-doc-9.16.23-18.el9_4.12.noarch.rpm SHA-256: c0a5dbf5c5684918d35b9f4c96e94bc95dfad541e6e03f478779aae959735c5c bind-dnssec-utils-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 5a8d923b89b3cb8a92490b57481e1527d5ec090fed75295f405775f6c2327a54 bind-dnssec-utils-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 4cbe7851bc8e02e02405c6a108b6889d78affb81fa9cd36af838cba51dca9053 bind-libs-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 8eaaa79dd383d9653b882a817d0fcd2798daf8bd9e1a1facc3c45eaf6e45104e bind-libs-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 01b5e2a87615fcb818875d0da1ee927f70e6bbe395ee2bc159009d890df3bc96 bind-license-9.16.23-18.el9_4.12.noarch.rpm SHA-256: 7182b2ab7c009a4f230cb0620999cc3653b5ca4e01d11c8fd681149e5ae8458b bind-utils-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 1cad8060d9f87e86af7ba103ee16f3ae00592335646cdfab173af3e5ce861c96 bind-utils-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: d08d0a5bacb80bca835f799cc179726fa2aefdb79664bed8c0dd7d60be4ca48c python3-bind-9.16.23-18.el9_4.12.noarch.rpm SHA-256: 2009c63bdeab1bf7221a1944694c9369caf8f3a315b46d30bd73cd7eebbaa4e3 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM bind-9.16.23-18.el9_4.12.src.rpm SHA-256: f6c9c58fe29753fe89099af70aae6dba0d1e9f9bc372df3bfe5c157d257dcfdf ppc64le bind-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: 577035b2ba9584eebf3fa5a6e32f07013e16920a8c4d0420f47fea20738fa225 bind-chroot-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: bed79b41aa05a791d608d5f606034a7741a9423310e4aefd1acae07d87b8e1ca bind-debuginfo-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: dcd3242bdda87e15702041252c9cf5d8bf7bb98a4fc529aaabdd1a2740e56566 bind-debugsource-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: 355fc59633e55064b267ea7f30a5b2e0bf24b0b2299afe343656577049639a57 bind-dnssec-doc-9.16.23-18.el9_4.12.noarch.rpm SHA-256: c0a5dbf5c5684918d35b9f4c96e94bc95dfad541e6e03f478779aae959735c5c bind-dnssec-utils-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: 269d38d5d7c60bd5c3610425b5de623cebd2ca99a5ad7cc94fb0deaacc878c38 bind-dnssec-utils-debuginfo-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: fc9d549ed0d6987b7cc93bb3bae6cac273bb2db3f17f4fb9782a7aafa9a95c0b bind-libs-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: 54e840661058478bc9b5ae3701dbf614bda98a379f0d2ed772e1dd1950cdbfc6 bind-libs-debuginfo-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: 7bf2b46c9b1b4a1b9fdb7cb7ee24184f7c4319e02d56f90f150b39e5bf426026 bind-license-9.16.23-18.el9_4.12.noarch.rpm SHA-256: 7182b2ab7c009a4f230cb0620999cc3653b5ca4e01d11c8fd681149e5ae8458b bind-utils-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: db383ae0a5127b1033440a8569579d69a6ef1804c9b3458c0e16296bb1c11007 bind-utils-debuginfo-9.16.23-18.el9_4.12.ppc64le.rpm SHA-256: a0362341922d8b9cd28e11c7cf6686a4cb85a6fa308390b52164bb7a62aed89b python3-bind-9.16.23-18.el9_4.12.noarch.rpm SHA-256: 2009c63bdeab1bf7221a1944694c9369caf8f3a315b46d30bd73cd7eebbaa4e3 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM bind-9.16.23-18.el9_4.12.src.rpm SHA-256: f6c9c58fe29753fe89099af70aae6dba0d1e9f9bc372df3bfe5c157d257dcfdf x86_64 bind-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: d979d43dc308728a56b0df1d1fadad699966e79ed6a0f7a2ce65e46bb8db19e6 bind-chroot-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 102a5db9aabe91e209f79fcf53aec4e743d9240f8c8dc0c2ed3efb6214801d3b bind-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 571a2b8e2ed9fdf69a6279d635e9d33057a5dd004980eb2f44add600e7340885 bind-debugsource-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 51ef8bd6e7cec7ff96e5ea139b40fc244ce2060d5c446df3fbe47e9c4bb3df11 bind-dnssec-doc-9.16.23-18.el9_4.12.noarch.rpm SHA-256: c0a5dbf5c5684918d35b9f4c96e94bc95dfad541e6e03f478779aae959735c5c bind-dnssec-utils-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 5a8d923b89b3cb8a92490b57481e1527d5ec090fed75295f405775f6c2327a54 bind-dnssec-utils-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 4cbe7851bc8e02e02405c6a108b6889d78affb81fa9cd36af838cba51dca9053 bind-libs-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 8eaaa79dd383d9653b882a817d0fcd2798daf8bd9e1a1facc3c45eaf6e45104e bind-libs-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 01b5e2a87615fcb818875d0da1ee927f70e6bbe395ee2bc159009d890df3bc96 bind-license-9.16.23-18.el9_4.12.noarch.rpm SHA-256: 7182b2ab7c009a4f230cb0620999cc3653b5ca4e01d11c8fd681149e5ae8458b bind-utils-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: 1cad8060d9f87e86af7ba103ee16f3ae00592335646cdfab173af3e5ce861c96 bind-utils-debuginfo-9.16.23-18.el9_4.12.x86_64.rpm SHA-256: d08d0a5bacb80bca835f799cc179726fa2aefdb79664bed8c0dd7d60be4ca48c python3-bind-9.16.23-18.el9_4.12.noarch.rpm SHA-256: 2009c63bdeab1bf7221a1944694c9369caf8f3a315b46d30bd73cd7eebbaa4e3 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM bind-9.16.23-18.el9_4.12.src.rpm SHA-256: f6c9c58fe29753fe89099af70aae6dba0d1e9f9bc372df3bfe5c157d257dcfdf aarch64 bind-9.16.23-18.el9_4.12.aarch64.rpm SHA-256: 39aecf294d271d060886f47fd8ca6513a4ce967799b7ae27c33435abe1f7b734 bind-chroot-9.16.23-18.el9_4.12.aarch64.rpm SHA-256: db24a461b7c36a532cb5b8f0bf3ec9cb125bfe3e1662d6517eab4eb03efcc156 bind-debuginfo-9.16.23-18.el9_4.12.aarch64.rpm SHA-256: c91564cba3b013f658871d2669e1d2259cc5428b5266cfba764e1a5dc2878322 bind-debugsource-9.16.23-18.el9_4.12.aarch64.rpm SHA-256: 55736262a87894d70a631716a845d9868c56e932b52f22c1e11e72a0d00cc224 bind-dnssec-doc-9.16.23-18.el9_4.12.noarch.rpm SHA-256: c0a5dbf5c5684918d35b9f4c96e94bc95dfad541e6e03f478779aae959735c5c bind-dnssec-utils-9.16.23-18.el9_4.12.aarch64.rpm SHA-256: da731a4348a74b4bd4c113e76c21aba492ba71c6ca7cd0e35daff265ffdfc584 bind-dnssec-utils-debuginfo-9.16.23-18.el9_4.12.

Share this article