Debian Package Tracker
Register | Log in
Subscribe

bind9

Internet Domain Name Server

Choose email to subscribe with

general
  • source: bind9 (main)
  • version: 1:9.20.29-1
  • maintainer: Debian DNS Team (DMD)
  • uploaders: Ondřej Surý [DMD] – Bernhard Schmidt [DMD]
  • arch: all any
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:9.16.50-1~deb11u2
  • o-o-sec: 1:9.16.50-1~deb11u6
  • o-o-p-u: 1:9.16.50-1~deb11u2
  • oldstable: 1:9.18.49-1~deb12u1
  • old-sec: 1:9.18.49-1~deb12u2
  • old-bpo: 1:9.20.26-1~deb13u1~bpo12+1
  • old-p-u: 1:9.18.49-1~deb12u1
  • stable: 1:9.20.23-1~deb13u1
  • stable-sec: 1:9.20.29-1~deb13u1
  • stable-p-u: 1:9.20.29-1~deb13u1
  • testing: 1:9.20.29-1
  • unstable: 1:9.20.29-1
  • exp: 1:9.21.26-1
versioned links
  • 1:9.16.50-1~deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.16.50-1~deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.18.49-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.18.49-1~deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.20.4-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.20.23-1~deb13u1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.20.23-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.20.26-1~deb13u1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.20.29-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.20.29-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.21.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:9.21.26-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • bind9 (17 bugs: 0, 12, 5, 0)
  • bind9-dev
  • bind9-dnsutils (1 bugs: 0, 1, 0, 0)
  • bind9-doc (3 bugs: 0, 2, 1, 0)
  • bind9-host (1 bugs: 0, 1, 0, 0)
  • bind9-libs (2 bugs: 0, 0, 2, 0)
  • bind9-utils (1 bugs: 0, 1, 0, 0)
action needed
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.

https://salsa.debian.org/api/v4/projects/dns-team%2Fbind9 API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2023-04-21 Last update: 2026-09-25 15:34
15 security issues in bookworm high

There are 15 open security issues in bookworm.

14 important issues:
  • CVE-2026-19033: For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-19662: An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-19666: On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-19667: If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-19668: A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-19941: An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-75029: In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-76163: If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-77119: A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-77692: An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-78301: A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On a server that also provides recursion BIND can follow this locally sourced cut and cache attacker-supplied data, affecting names outside the configured zone. This situation persists as long as the malformed zone remains in the zone database. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-80274: If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-81563: A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
  • CVE-2026-81736: If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
1 issue postponed or untriaged:
  • CVE-2025-40777: (postponed; to be fixed through a stable update) If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.
Created: 2026-09-16 Last update: 2026-09-19 17:31
2 security issues in buster high

There are 2 open security issues in buster.

1 important issue:
  • CVE-2023-4408: The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
1 ignored issue:
  • CVE-2022-3094: Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of internal resources rather than memory constraints. This may reduce performance but should not be a significant problem for most servers. Therefore we don't intend to address this for BIND versions prior to BIND 9.16. This issue affects BIND 9 versions 9.16.0 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.8-S1 through 9.16.36-S1.
Created: 2024-02-13 Last update: 2024-06-29 13:15
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • dnsutils could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2026-09-27 06:01
Depends on packages which need a new maintainer normal
The packages that bind9 depends on which need a new maintainer are:
  • db-defaults (#1055344)
    • Build-Depends: libdb-dev
Created: 2023-11-04 Last update: 2026-09-27 06:00
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-27 05:00
lintian reports 7 warnings normal
Lintian reports 7 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-02 Last update: 2026-09-02 06:01
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 1:9.20.29-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-09-16 19:20
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2020-03-24 Last update: 2020-03-24 06:20
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.2).
Created: 2024-04-07 Last update: 2026-09-16 19:30
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-09-21] Accepted bind9 1:9.20.29-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-09-19] bind9 1:9.20.29-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-17] Accepted bind9 1:9.20.29-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-09-16] Accepted bind9 1:9.21.26-1 (source) into experimental (Ondřej Surý)
  • [2026-09-16] Accepted bind9 1:9.20.29-1 (source) into unstable (Ondřej Surý)
  • [2026-09-06] bind9 1:9.20.27-2 MIGRATED to testing (Debian testing watch)
  • [2026-09-01] Accepted bind9 1:9.20.27-2 (source) into unstable (Bernhard Schmidt)
  • [2026-08-25] bind9 1:9.20.27-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-19] Accepted bind9 1:9.21.25-1 (source) into experimental (Ondřej Surý)
  • [2026-08-19] Accepted bind9 1:9.20.27-1 (source) into unstable (Ondřej Surý)
  • [2026-08-08] Accepted bind9 1:9.16.50-1~deb11u6 (source) into oldoldstable-security (Emmanuel Arias)
  • [2026-08-07] Accepted bind9 1:9.18.49-1~deb12u2 (source) into oldstable-security (Emmanuel Arias)
  • [2026-07-28] bind9 1:9.20.26-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-23] Accepted bind9 1:9.20.26-1~deb13u1~bpo12+1 (source) into oldstable-backports (Bernhard Schmidt)
  • [2026-07-23] Accepted bind9 1:9.20.26-1 (source) into unstable (Ondřej Surý)
  • [2026-07-23] Accepted bind9 1:9.20.26-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-07-22] Accepted bind9 1:9.20.26-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-06-26] bind9 1:9.20.24-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-17] Accepted bind9 1:9.21.23-1 (source) into experimental (Ondřej Surý)
  • [2026-06-17] Accepted bind9 1:9.20.24-1 (source) into unstable (Ondřej Surý)
  • [2026-06-14] Accepted bind9 1:9.20.23-1~deb13u1~bpo12+1 (source) into oldstable-backports (Bernhard Schmidt)
  • [2026-05-24] bind9 1:9.20.23-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-23] Accepted bind9 1:9.20.23-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-05-22] Accepted bind9 1:9.18.49-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-05-20] Accepted bind9 1:9.21.22-1 (source) into experimental (Ondřej Surý)
  • [2026-05-20] Accepted bind9 1:9.20.23-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-05-20] Accepted bind9 1:9.18.49-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Ondřej Surý)
  • [2026-05-20] Accepted bind9 1:9.20.23-1 (source) into unstable (Ondřej Surý)
  • [2026-04-13] Accepted bind9 1:9.16.50-1~deb11u5 (source) into oldoldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2026-04-04] bind9 1:9.20.22-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 27 28
  • RC: 0
  • I&N: 16 17
  • M&W: 11
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian (0, 7)
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (100, -)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:9.20.24-1ubuntu3
  • 66 bugs (4 patches)
  • patches for 1:9.20.24-1ubuntu3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing