openSUSE-SU-2026:20091-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20091-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20091-1
Upstream
  • CVE-2025-13878
Related
  • CVE-2025-13878
Published
2026-01-22T16:45:35Z
Modified
2026-03-23T04:54:44.067379Z
Summary
Security update for bind
Details

This update for bind fixes the following issues:

Upgrade to release 9.20.18:

  • CVE-2025-13878: Fixed incorrect length checks for BRID and HHIT records (bsc#1256997)

    Feature Changes:

    • Add more information to the rndc recursing output about fetches.
    • Reduce the number of outgoing queries.
    • Provide more information when memory allocation fails.

    Bug Fixes:

    • Make DNSSEC key rollovers more robust.
    • Fix a catalog zone issue, where member zones could fail to load.
    • Allow glue in delegations with QTYPE=ANY.
    • Fix slow speed when signing a large delegation zone with NSEC3 opt-out.
    • Reconfiguring an NSEC3 opt-out zone to NSEC caused the zone to be invalid.
    • Fix a possible catalog zone issue during reconfiguration.
    • Fix the charts in the statistics channel.
    • Adding NSEC3 opt-out records could leave invalid records in chain.
    • Fix spurious timeouts while resolving names.
    • Fix bug where zone switches from NSEC3 to NSEC after retransfer.
    • AMTRELAY type 0 presentation format handling was wrong.
    • Fix parsing bug in remote-servers with key or TLS.
    • Fix DoT reconfigure/reload bug in the resolver.
    • Skip unsupported algorithms when looking for a signing key.
    • Fix dnssec-keygen key collision checking for KEY RRtype keys.
    • dnssec-verify now uses exit code 1 when failing due to illegal options.
    • Prevent assertion failures of dig when a server is specified before the -b option.
    • Skip buffer allocations if not logging.
References

Affected packages

openSUSE:Leap 16.0 / bind

Package

Name
bind
Purl
pkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.20.18-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "bind-modules-perl": "9.20.18-160000.1.1",
            "bind": "9.20.18-160000.1.1",
            "bind-doc": "9.20.18-160000.1.1",
            "bind-modules-ldap": "9.20.18-160000.1.1",
            "bind-modules-bdbhpt": "9.20.18-160000.1.1",
            "bind-modules-generic": "9.20.18-160000.1.1",
            "bind-modules-sqlite3": "9.20.18-160000.1.1",
            "bind-utils": "9.20.18-160000.1.1",
            "bind-modules-mysql": "9.20.18-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20091-1.json"