OESA-2026-4192

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-4192
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-4192.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-4192
Upstream
CVE (3)
  • CVE-2026-80274
  • CVE-2026-81563
  • CVE-2026-81736
Published
2026-09-30T13:47:28Z
Modified
2026-10-01T02:00:06Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
bind security update
Details

Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.

Security Fix(es):

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-80274)

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-81563)

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-81736)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / bind

Package

Name
bind
Purl
pkg:rpm/openEuler/bind&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.18.21-14.oe2403sp3

Ecosystem specific

{
    "aarch64": [
        "bind-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-chroot-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-debuginfo-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-debugsource-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-devel-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-dnssec-utils-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-libs-9.18.21-14.oe2403sp3.aarch64.rpm",
        "bind-utils-9.18.21-14.oe2403sp3.aarch64.rpm"
    ],
    "noarch": [
        "bind-dnssec-doc-9.18.21-14.oe2403sp3.noarch.rpm",
        "bind-license-9.18.21-14.oe2403sp3.noarch.rpm"
    ],
    "src": [
        "bind-9.18.21-14.oe2403sp3.src.rpm"
    ],
    "x86_64": [
        "bind-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-chroot-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-debuginfo-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-debugsource-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-devel-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-dnssec-utils-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-libs-9.18.21-14.oe2403sp3.x86_64.rpm",
        "bind-utils-9.18.21-14.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-4192.json"