SUSE-SU-2026:20085-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202620085-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20085-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:20085-1
Upstream
CVE (3)
  • CVE-2025-40778
  • CVE-2025-40780
  • CVE-2025-8677
Related
Published
2026-01-15T10:43:50Z
Modified
2026-03-23T04:52:34Z
Summary
Security update for bind
Details

This update for bind fixes the following issues:

  • Upgrade to release 9.20.15 Security Fixes:

    • CVE-2025-40778: Fixed cache poisoning attacks with unsolicited RRs (bsc#1252379)
    • CVE-2025-40780: Fixed cache poisoning due to weak PRNG (bsc#1252380)
    • CVE-2025-8677: Fixed resource exhaustion via malformed DNSKEY handling (bsc#1252378)

    New Features:

    • Add dnssec-policy keys configuration check to named-checkconf.
    • Add a new option manual-mode to dnssec-policy.
    • Add a new option servfail-until-ready to response-policy zones.
    • Support for parsing HHIT and BRID records has been added.
    • Support for parsing DSYNC records has been added.

    Removed Features:

    • Deprecate the tkey-gssapi-credential statement.
    • Obsolete the tkey-domain statement.

    Feature Changes:

    • Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1, and DS digest type 1.

    Bug Fixes:

    • Missing DNSSEC information when CD bit is set in query.
    • rndc sign during ZSK rollover will now replace signatures.
    • Use signer name when disabling DNSSEC algorithms.
    • Preserve cache when reload fails and reload the server again.
    • Prevent spurious SERVFAILs for certain 0-TTL resource records.
    • Fix unexpected termination if catalog-zones had undefined default-primaries.
    • Stale RRsets in a CNAME chain were not always refreshed.
    • Add RPZ extended DNS error for zones with a CNAME override policy configured.
    • Fix dig +keepopen option.
    • Log dropped or slipped responses in the query-errors category.
    • Fix synth-from-dnssec not working in some scenarios.
    • Clean enough memory when adding new ADB names/entries under memory pressure.
    • Prevent spurious validation failures.
    • Ensure file descriptors 0-2 are in use before using libuv [bsc#1230649]
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.20.15-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "bind":  "9.20.15-160000.1.1",
            "bind-doc":  "9.20.15-160000.1.1",
            "bind-modules-generic":  "9.20.15-160000.1.1",
            "bind-modules-ldap":  "9.20.15-160000.1.1",
            "bind-modules-mysql":  "9.20.15-160000.1.1",
            "bind-modules-perl":  "9.20.15-160000.1.1",
            "bind-modules-sqlite3":  "9.20.15-160000.1.1",
            "bind-utils":  "9.20.15-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20085-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.20.15-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "bind":  "9.20.15-160000.1.1",
            "bind-doc":  "9.20.15-160000.1.1",
            "bind-modules-generic":  "9.20.15-160000.1.1",
            "bind-modules-ldap":  "9.20.15-160000.1.1",
            "bind-modules-mysql":  "9.20.15-160000.1.1",
            "bind-modules-perl":  "9.20.15-160000.1.1",
            "bind-modules-sqlite3":  "9.20.15-160000.1.1",
            "bind-utils":  "9.20.15-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:20085-1.json"