SUSE alert SUSE-SU-2026:3426-1 (bind)
| From: | SLE-SECURITY-UPDATES <null@suse.de> | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2026:3426-1: important: Security update for bind | |
| Date: | Thu, 30 Jul 2026 16:34:06 -0000 | |
| Message-ID: | <178542924691.1270.10423652701822853138@cdce4c525ac1> |
# Security update for bind Announcement ID: SUSE-SU-2026:3426-1 Release Date: 2026-07-30T11:12:13Z Rating: important References: * bsc#1271982 * bsc#1271983 * bsc#1271984 * bsc#1271985 * bsc#1271986 * bsc#1271987 * bsc#1271988 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2026-10723 * CVE-2026-10822 * CVE-2026-11331 * CVE-2026-11605 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-12617 * CVE-2026-13204 * CVE-2026-13321 CVSS scores: * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10822 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10822 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-10822 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11605 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11605 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-12617 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12617 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12617 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: Upgrade to release 9.20.26. Security issues fixed: * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected exit (bsc#1271983). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11605: unnecessary validation of DNSSEC signed records (bsc#1271985). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME (bsc#1271988). * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). Other updates and bugfixes: * Release 9.20.26: * Reclaim memory promptly when DNSSEC validations are canceled. * Removed Features: * Remove the secondary validator in query.c. * Remove ineffective TCP fallback after repeated UDP timeouts. * Feature Changes: * Fall back to TCP on receipt of a UDP response with a mismatched query ID. * Limit the number of glue records cached from a referral. * Fix a resolver stall on a CNAME response to a DS query. * Bug Fixes: * Fix a bug in DNS UPDATE processing with inline-signing enabled. * Properly detect private records before copying. * Tighten referral DS acceptance. * Don't synthesize negative responses with pending NSEC. * Check that an NSEC signer is at or above the name to be validated. * Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN. * Fix a deny-answer-aliases configuration bypass issue. * Reject external referrals from forwarders. * Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode. * Unvalidated opt-out NSEC3 could be accepted in insecurity proof. * Check wildcard signer and NOQNAME signer match. * Fix CNAME resolution failure caused by a cached SERVFAIL response. * Reject unsupported RSA DNSKEY shapes during DNSSEC validation. * Fix a bug in GeoIP2 string matching. * Fix DNS-over-HTTPS (DoH) quota configuration issue. * Truncated reply to a TSIG query no longer stalls the resolver. * Ignore updates removing DNSKEY RRset with class ANY. * Ignore 0-byte reads in the TCP read callback. * Only print per-zone glue stats when zone-statistics is set to full. * CDS/CDNSKEY records were not removed when re-configuring the server. * Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB. * Stop reusing outgoing TCP connections the peer has already closed. * Fix DNSSEC validation failures for names under an apex DNAME. * The resolver now removes other RRsets at the same name when caching a CNAME. * Fix nxdomain-redirect combined with dns64. * Fix DNS64 owner case after DNAME restart. * Clear REDIRECT flag when it isn't needed. * Disable output escaping in bind9.xsl. * Fix crash on badly configured secondary signer. * Fix a possible crash on concurrent TKEY DELETE for the same key. * Reject RRSIG records covering meta-types. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3426=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3426=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bind-utils-9.20.26-150700.3.29.1 * bind-debugsource-9.20.26-150700.3.29.1 * bind-utils-debuginfo-9.20.26-150700.3.29.1 * bind-debuginfo-9.20.26-150700.3.29.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bind-debuginfo-9.20.26-150700.3.29.1 * bind-debugsource-9.20.26-150700.3.29.1 * bind-9.20.26-150700.3.29.1 * Server Applications Module 15-SP7 (noarch) * bind-doc-9.20.26-150700.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-10822.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11605.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-12617.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271983 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271985 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271988 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990
Attachment: None (type=text/html)
(HTML attachment elided)
