SUSE-SU-2026:3426-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263426-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3426-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3426-1
Upstream
CVE (9)
  • CVE-2026-10723
  • CVE-2026-10822
  • CVE-2026-11331
  • CVE-2026-11605
  • CVE-2026-11622
  • CVE-2026-11721
  • CVE-2026-12617
  • CVE-2026-13204
  • CVE-2026-13321
Related
Published
2026-07-30T11:12:12Z
Modified
2026-07-31T09:15:07Z
Summary
Security update for bind
Details

This update for bind fixes the following issues:

Upgrade to release 9.20.26.

Security issues fixed:

  • CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
  • CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected exit (bsc#1271983).
  • CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
  • CVE-2026-11605: unnecessary validation of DNSSEC signed records (bsc#1271985).
  • CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986).
  • CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).
  • CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME (bsc#1271988).
  • CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989).
  • CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990).

Other updates and bugfixes:

  • Release 9.20.26:
    • Reclaim memory promptly when DNSSEC validations are canceled.
    • Removed Features:
      • Remove the secondary validator in query.c.
      • Remove ineffective TCP fallback after repeated UDP timeouts.
    • Feature Changes:
      • Fall back to TCP on receipt of a UDP response with a mismatched query ID.
      • Limit the number of glue records cached from a referral.
      • Fix a resolver stall on a CNAME response to a DS query.
    • Bug Fixes:
      • Fix a bug in DNS UPDATE processing with inline-signing enabled.
      • Properly detect private records before copying.
      • Tighten referral DS acceptance.
      • Don't synthesize negative responses with pending NSEC.
      • Check that an NSEC signer is at or above the name to be validated.
      • Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN.
      • Fix a deny-answer-aliases configuration bypass issue.
      • Reject external referrals from forwarders.
      • Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode.
      • Unvalidated opt-out NSEC3 could be accepted in insecurity proof.
      • Check wildcard signer and NOQNAME signer match.
      • Fix CNAME resolution failure caused by a cached SERVFAIL response.
      • Reject unsupported RSA DNSKEY shapes during DNSSEC validation.
      • Fix a bug in GeoIP2 string matching.
      • Fix DNS-over-HTTPS (DoH) quota configuration issue.
      • Truncated reply to a TSIG query no longer stalls the resolver.
      • Ignore updates removing DNSKEY RRset with class ANY.
      • Ignore 0-byte reads in the TCP read callback.
      • Only print per-zone glue stats when zone-statistics is set to full.
      • CDS/CDNSKEY records were not removed when re-configuring the server.
      • Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB.
      • Stop reusing outgoing TCP connections the peer has already closed.
      • Fix DNSSEC validation failures for names under an apex DNAME.
        • The resolver now removes other RRsets at the same name when caching a CNAME.
      • Fix nxdomain-redirect combined with dns64.
      • Fix DNS64 owner case after DNAME restart.
      • Clear REDIRECT flag when it isn't needed.
      • Disable output escaping in bind9.xsl.
      • Fix crash on badly configured secondary signer.
      • Fix a possible crash on concurrent TKEY DELETE for the same key.
      • Reject RRSIG records covering meta-types.
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.20.26-150700.3.29.1

Ecosystem specific

{
    "binaries":  [
        {
            "bind-utils":  "9.20.26-150700.3.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3426-1.json"
SUSE:Linux Enterprise Module for Server Applications 15 SP7
bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.20.26-150700.3.29.1

Ecosystem specific

{
    "binaries":  [
        {
            "bind":  "9.20.26-150700.3.29.1",
            "bind-doc":  "9.20.26-150700.3.29.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3426-1.json"