SUSE-SU-2026:3452-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263452-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3452-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3452-1
Upstream
CVE (8)
  • CVE-2026-10723
  • CVE-2026-10822
  • CVE-2026-11331
  • CVE-2026-11622
  • CVE-2026-11721
  • CVE-2026-12617
  • CVE-2026-13204
  • CVE-2026-13321
Related
Published
2026-08-03T11:34:55Z
Modified
2026-08-04T11:45:06Z
Summary
Security update for bind
Details

This update for bind fixes the following issues:

  • CVE-2026-10723: accepting incorrect child-zone NSEC3 records as valid can allow an attacker to forge authenticated NXDOMAIN responses for sibling zones (bsc#1271982).

  • CVE-2026-10822: storing a DNS key record with an invalid PRIVATEDNS algorithm identifier length can trigger a consistency check failure (bsc#1271983).

  • CVE-2026-11331: handling NAMETOOLONG error conditions incorrectly during RPZ wildcard CNAME processing can allow bypassing RPZ rules or triggering process exits (bsc#1271984).

  • CVE-2026-11622: DNSSEC validating resolver under a random subdomain attack can suffer from runaway memory usage exceeding max-cache-size and affecting response rate (bsc#1271986).

  • CVE-2026-11721: RRSIG with fewer labels than its containing zone when synth-from-dnssec is enabled can lead to wildcard generation (bsc#1271987).

  • CVE-2026-12617: delayed or specific CNAME/DNAME query responses combined with positive A record responses can trigger an assertion failure (bsc#1271988).

  • CVE-2026-13204: validating a domain covered by both NSEC and NSEC3 with an RRSIG for only one type can trigger an assertion failure (bsc#1271989).

  • CVE-2026-13321: NSEC records with a Next Domain Name pointing outside the signer's zone can allow cross-zone cache poisoning and authenticated denial-of-service responses (bsc#1271990).

  • Update to release 9.18.50:

  • Remove ineffective TCP fallback after repeated UDP timeouts.
  • Fall back to TCP on receipt of a UDP response with a mismatched query ID.
  • Fix DNS64 owner case after DNAME restart.
  • Clear REDIRECT flag when it isn't needed.
References

Affected packages

SUSE:Linux Enterprise Server 15 SP6-LTSS / bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.18.50-150600.3.32.1

Ecosystem specific

{
    "binaries":  [
        {
            "bind":  "9.18.50-150600.3.32.1",
            "bind-doc":  "9.18.50-150600.3.32.1",
            "bind-utils":  "9.18.50-150600.3.32.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3452-1.json"

SUSE:Linux Enterprise Server for SAP Applications 15 SP6 / bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.18.50-150600.3.32.1

Ecosystem specific

{
    "binaries":  [
        {
            "bind":  "9.18.50-150600.3.32.1",
            "bind-doc":  "9.18.50-150600.3.32.1",
            "bind-utils":  "9.18.50-150600.3.32.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3452-1.json"