MGASA-2026-0331

Source
https://advisories.mageia.org/MGASA-2026-0331.html
Import Source
https://advisories.mageia.org/MGASA-2026-0331.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0331
Upstream
  • CVE-2026-10723
  • CVE-2026-10822
  • CVE-2026-11331
  • CVE-2026-11605
  • CVE-2026-11721
  • CVE-2026-12617
  • CVE-2026-13204
  • CVE-2026-13321
Published
2026-08-10T19:29:27Z
Modified
2026-08-15T18:00:03.561699670Z
Summary
Updated bind packages fix security vulnerabilities
Details

Updated bind packages fix security vulnerabilities: Incorrect acceptance of NSEC3 records. (CVE-2026-10723) Key Record using PRIVATEDNS algorithm may lead to unexpected exit. (CVE-2026-10822) Potential wildcard CNAME RPZ policy bypass. (CVE-2026-11331) Unnecessary validation of DNSSEC signed records. (CVE-2026-11605) Cache poisoning possible with label count discrepancy, RRSIG, and wildcards. (CVE-2026-11721) Record ordering based unexpected exit with CNAME or DNAME. (CVE-2026-12617) Unexpected exit in certain situations with NSEC and NSEC3 both present. (CVE-2026-13204) DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field. (CVE-2026-13321)

References
Credits

Affected packages

Mageia:10 / bind

Package

Name
bind
Purl
pkg:rpm/mageia/bind?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.20.26-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0331.json"