-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 31 Jul 2026 18:11:43 -0300 Source: bind9 Architecture: source Version: 1:9.18.49-1~deb12u2 Distribution: bookworm-security Urgency: high Maintainer: Debian DNS Team <team+dns@tracker.debian.org> Changed-By: Emmanuel Arias <eamanu@debian.org> Changes: bind9 (1:9.18.49-1~deb12u2) bookworm-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2026-10723: Correct verification of NSEC3 signer name. BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. * CVE-2026-10822: Malformed DNSKEY records could trigger an assertion. If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. The invalid identifier will be stored. * CVE-2026-11331: Fix handling of RPZ CNAME expansion that returns too-long name. An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. * CVE-2026-11622: Prevent cache exhaustion under sustained attack. A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. - Also fix CVE-2026-11605. * CVE-2026-11721: Stop accepting invalid signed wildcard records. It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. * CVE-2026-12617: Do not assert for some specific CNAME and DNAME queries.The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. * CVE-2026-13204: Prevent crash from malformed NSEC/NSEC3 response. If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. * CVE-2026-13321: Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. The BIND resolver accepts validly-signed NSEC records where the 'Next Domain Name' field points outside the signe's zone. Checksums-Sha1: 1de30c85bd4238a5a0f9d3f7e979ffadf2465201 3220 bind9_9.18.49-1~deb12u2.dsc 76b97204dfa8fc02526b9d67b5e89e4dc8a600db 5476288 bind9_9.18.49.orig.tar.xz c2bede70d7e9b074fb26a1ab7379cbd006597ecc 833 bind9_9.18.49.orig.tar.xz.asc e0fecfe722d1054ce254be912bed67bc6391e645 93512 bind9_9.18.49-1~deb12u2.debian.tar.xz caf0c63d0d5ae6dffeaeb98345b32f37a7f241ab 7234 bind9_9.18.49-1~deb12u2_source.buildinfo Checksums-Sha256: 9708100280a8c3a535fa196680dcb36ea6a60187019a2f34adc093c737837ceb 3220 bind9_9.18.49-1~deb12u2.dsc c43ce4548ebed788cd9df63658a7de105ceafba43fcd63fa352b1093e525cd24 5476288 bind9_9.18.49.orig.tar.xz 6b92ce3f446389b630b78b3f57c7c1279cc26f662fe5b2f4da318d0144d998a8 833 bind9_9.18.49.orig.tar.xz.asc 2b911f120a51431f6e25c5c6c8c6e6692f70b03b8499d2af985025fb0193068f 93512 bind9_9.18.49-1~deb12u2.debian.tar.xz 25e0c29fd328936bfd80d4ce145fb39daa77fda815e2458d2a7bfaef6287852f 7234 bind9_9.18.49-1~deb12u2_source.buildinfo Files: d1ca4c770577f5fbd0150d951411cbe7 3220 net optional bind9_9.18.49-1~deb12u2.dsc 1440019616b56a6e32c8f6b52bd07583 5476288 net optional bind9_9.18.49.orig.tar.xz 19dc764f9a132a91ce95162f40cf272b 833 net optional bind9_9.18.49.orig.tar.xz.asc a673fc704722f7ba5a3ad01c3da38fa2 93512 net optional bind9_9.18.49-1~deb12u2.debian.tar.xz db7248aef60979b4e53bac28c1bc1032 7234 net optional bind9_9.18.49-1~deb12u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJGBAEBCgAwFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmp15acSHGVhbWFudUBk ZWJpYW4ub3JnAAoJEPqd7F3hHGPxkNoP/0fLZYKv0UK77OJkVnTpjnWBMcYQPrJx 53kkaalKKLs1ylD0QIVanocHn7u0Gr9TVo5rkvQmGyRiG6fwR1Ehapk5JMcWNBVT 68GL8eJw72IG+miA3iUsqwYuM/AnUKN8Lc3Va7yyEQYFIQFZ2JBEeXn/Pkrw19iz Bbl2q2vWLUtHY5QBokkGNaikhbDQcoEJNlobesafwTMwpeQeNjuhKg5qpC59Gqma l4cOzrGYolphAXqTx9xIw30SJUsv1QQEWkEyJ+EiHp0atLrgJA6gc7uLg0iIXpOh MJb3iNmDDQh01SpLTtF5c4yDNhjTLeRzammY5VAAbBvrZgBk2SNgouOJZu6f2LIF vzKTvBTgR44J6lsAXYyzxsET9gK4/sN8KOWqg/eOn8k3s5PFhwsIxmpFIQ5xodCh MVNj70XfGbsZJoc1albUoPRO8Q15e5jvDtLUrb6uyG9u/Cj/S7JVnCjy95Al0EQb nQ6XmjzoO5qr3jQ8/PEESBZk5DYL1+O0rvyEQV7aWtlZGVMRZhOL23puLGEo1jME 9zzG3JV/FvH6sIEjYPaMGlq9VN+h2UdaP1XhwGJTH4YJJcGNP0U9PqpBNjv6lq9x gez/t8HBrBNOTnmqJX9nK3ckd2jJAzlAq1bBhYqBsxgbhyn/X1L/59Gz3+S8dG/+ fcJR9kqCE0OY =N3nv -----END PGP SIGNATURE-----