-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 29 Jun 2026 00:24:50 -0300 Source: bind9 Architecture: source Version: 1:9.16.50-1~deb11u6 Distribution: bullseye-security Urgency: high Maintainer: Debian DNS Team <team+dns@tracker.debian.org> Changed-By: Emmanuel Arias <eamanu@debian.org> Changes: bind9 (1:9.16.50-1~deb11u6) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2026-5950: An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. * CVE-2026-5946: Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (IN) or DNS messages that specify meta-classes (ANY or NONE) in the question section. * CVE-2026-3592: BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. * CVE-2026-3039: BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. * CVE-2026-11331: Fix handling of RPZ CNAME expansion that returns too-long name. An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. * CVE-2026-11622: Prevent cache exhaustion under sustained attack. A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. - Also fix CVE-2026-11605. * CVE-2026-11721: Stop accepting invalid signed wildcard records. It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. * CVE-2026-10723: Correct verification of NSEC3 signer name. BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. * CVE-2026-13204: Prevent crash from malformed NSEC/NSEC3 response. If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. * CVE-2026-13321: Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. The BIND resolver accepts validly-signed NSEC records where the 'Next Domain Name' field points outside the signe's zone. * d/source/options: Ignore Windows project files to fix build errors. * d/salsa-ci.yml: Enable salsa-ci. Checksums-Sha1: 672132bc39ee85d58efcbe6e7a89f9084cd7cd01 3164 bind9_9.16.50-1~deb11u6.dsc a10542aaabad60bbbb8d19efd43591c98c01c277 5134620 bind9_9.16.50.orig.tar.xz b0da42f81f0cf61e3daeaa08a86abd78e73d3937 833 bind9_9.16.50.orig.tar.xz.asc 17bad1c590057617b95cdd1510d090da0a3ff8e6 130352 bind9_9.16.50-1~deb11u6.debian.tar.xz 70eaf181e22f9e0b401bda4ffed33ee4ed6c8356 7236 bind9_9.16.50-1~deb11u6_source.buildinfo Checksums-Sha256: f3c07393a1cb60086abf53488c50aa42122e85989c76f66961cb8cbd7e256117 3164 bind9_9.16.50-1~deb11u6.dsc 816dbaa3c115019f30fcebd9e8ef8f7637f4adde91c79daa099b035255a15795 5134620 bind9_9.16.50.orig.tar.xz ea439870e59cb3b415a64d1f19a302f5c362538e4918a09528b22529426b4cc6 833 bind9_9.16.50.orig.tar.xz.asc 8de28c840c79da597d5264464b7e122cd0af103b1c75e593a75db6ecadff0d59 130352 bind9_9.16.50-1~deb11u6.debian.tar.xz 05d520acf9c406c00bd105b52e120d1ea8b439f9f9e35f767f0bbd74f66e9e65 7236 bind9_9.16.50-1~deb11u6_source.buildinfo Files: 02a185b1647d7d1940d256b8da038d6e 3164 net optional bind9_9.16.50-1~deb11u6.dsc 0aa065323f039e413d234736a727c00e 5134620 net optional bind9_9.16.50.orig.tar.xz 7621fdb8536f44e0df9680c251aa9e95 833 net optional bind9_9.16.50.orig.tar.xz.asc 1f68fa23595ae25a041661ed555eac3e 130352 net optional bind9_9.16.50-1~deb11u6.debian.tar.xz ab6b1d2b0e3497b95e739349dfc9a82c 7236 net optional bind9_9.16.50-1~deb11u6_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJGBAEBCgAwFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmp3L1ISHGVhbWFudUBk ZWJpYW4ub3JnAAoJEPqd7F3hHGPxw2cQALbNDNDa7WHQdKyI1m6VY+7em63DZYo8 fB21iHC4BGkjOSHBRB01by+rpGWttvUFviU1yZ9spPf94YqXHj4+4rNoJ9LcH4Gn 4IM+jSb6zyLq0zDIyQM4dFXy8SvTlMLBt7jIMwPlEKVg8+08T9VKdE8kMYoYYbjt XGmE8SoRb8d1jSWrM0UjfVF7+6XADSbC/FVzhmApD17hfxQ/Z36S+a56Zbs1QGAo spfATfb5My4CTdjGqyccaGGyG2i9qkWm9ZQax8uE77GYwxBA2b6kRMcNfQ+r7tGz XIiEZIpjnDelfQW9XG4v3albdw2zDl4JekoIzYnPFrqVwr6/EUXBbSiCEstF3g1U glL6zTWWa3ElZdWhb7v395KIBenc2lmzyfdEX2oHk9nZ0AX6SiAFMf8+IWd9c4P9 EzNL359Qmcr6uGQWBesnQJsq7Q8xz1+EelITMBNi0gXV6wo3GD53e7mps8tPOvo9 U+4Ikeo71/adAJk4U2YjC25D8IxyuB4ZtcqRMXt0TnpPeShCo1v4aXxhWU8Bg7os TYTJI6Q6IXE5oVN5xJFIf3SCaLh1mR2NufP1TR/DP6ZweRbD48SPEjDjvq2ZKj63 zAg6uK8xLOyhb8KCjRx3zdc0BgAH75P7sljBCNVzJrmFCsG1dBetoIeJ6kUliRnI xg3XcQI3m0wm =OObd -----END PGP SIGNATURE-----