openSUSE-SU-2026:20039-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20039-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20039-1
Upstream
  • CVE-2025-40778
  • CVE-2025-40780
  • CVE-2025-8677
Related
  • CVE-2025-40778
  • CVE-2025-40780
  • CVE-2025-8677
Published
2026-01-15T10:43:49Z
Modified
2026-03-23T04:54:42.601949Z
Summary
Security update for bind
Details

This update for bind fixes the following issues:

  • Upgrade to release 9.20.15 Security Fixes:

    • CVE-2025-40778: Fixed cache poisoning attacks with unsolicited RRs (bsc#1252379)
    • CVE-2025-40780: Fixed cache poisoning due to weak PRNG (bsc#1252380)
    • CVE-2025-8677: Fixed resource exhaustion via malformed DNSKEY handling (bsc#1252378)

    New Features:

    • Add dnssec-policy keys configuration check to named-checkconf.
    • Add a new option manual-mode to dnssec-policy.
    • Add a new option servfail-until-ready to response-policy zones.
    • Support for parsing HHIT and BRID records has been added.
    • Support for parsing DSYNC records has been added.

    Removed Features:

    • Deprecate the tkey-gssapi-credential statement.
    • Obsolete the tkey-domain statement.

    Feature Changes:

    • Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1, and DS digest type 1.

    Bug Fixes:

    • Missing DNSSEC information when CD bit is set in query.
    • rndc sign during ZSK rollover will now replace signatures.
    • Use signer name when disabling DNSSEC algorithms.
    • Preserve cache when reload fails and reload the server again.
    • Prevent spurious SERVFAILs for certain 0-TTL resource records.
    • Fix unexpected termination if catalog-zones had undefined default-primaries.
    • Stale RRsets in a CNAME chain were not always refreshed.
    • Add RPZ extended DNS error for zones with a CNAME override policy configured.
    • Fix dig +keepopen option.
    • Log dropped or slipped responses in the query-errors category.
    • Fix synth-from-dnssec not working in some scenarios.
    • Clean enough memory when adding new ADB names/entries under memory pressure.
    • Prevent spurious validation failures.
    • Ensure file descriptors 0-2 are in use before using libuv [bsc#1230649]
References

Affected packages

openSUSE:Leap 16.0 / bind

Package

Name
bind
Purl
pkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.20.15-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "bind-modules-ldap": "9.20.15-160000.1.1",
            "bind-modules-sqlite3": "9.20.15-160000.1.1",
            "bind-modules-perl": "9.20.15-160000.1.1",
            "bind-utils": "9.20.15-160000.1.1",
            "bind-modules-mysql": "9.20.15-160000.1.1",
            "bind-modules-generic": "9.20.15-160000.1.1",
            "bind": "9.20.15-160000.1.1",
            "bind-modules-bdbhpt": "9.20.15-160000.1.1",
            "bind-doc": "9.20.15-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20039-1.json"