OESA-2026-3329

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3329
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3329.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3329
Upstream
  • CVE-2026-11622
Published
2026-08-13T13:57:56Z
Modified
2026-08-16T01:45:16.279909233Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
bind security update
Details

BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.

Security Fix(es):

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the max-cache-size parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.(CVE-2026-11622)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / bind

Package

Name
bind
Purl
pkg:rpm/openEuler/bind&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.18.21-12.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "bind-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-chroot-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-debuginfo-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-debugsource-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-devel-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-dnssec-utils-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-libs-9.18.21-12.oe2403sp3.x86_64.rpm",
        "bind-utils-9.18.21-12.oe2403sp3.x86_64.rpm"
    ],
    "aarch64": [
        "bind-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-chroot-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-debuginfo-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-debugsource-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-devel-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-dnssec-utils-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-libs-9.18.21-12.oe2403sp3.aarch64.rpm",
        "bind-utils-9.18.21-12.oe2403sp3.aarch64.rpm"
    ],
    "src": [
        "bind-9.18.21-12.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "bind-dnssec-doc-9.18.21-12.oe2403sp3.noarch.rpm",
        "bind-license-9.18.21-12.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3329.json"