SUSE-SU-2026:3426-1: important: Security update for bind

SLE-UPDATES null at suse.de
Thu Jul 30 16:33:50 UTC 2026


# Security update for bind

Announcement ID: SUSE-SU-2026:3426-1  
Release Date: 2026-07-30T11:12:13Z  
Rating: important  
References:

  * bsc#1271982
  * bsc#1271983
  * bsc#1271984
  * bsc#1271985
  * bsc#1271986
  * bsc#1271987
  * bsc#1271988
  * bsc#1271989
  * bsc#1271990

  
Cross-References:

  * CVE-2026-10723
  * CVE-2026-10822
  * CVE-2026-11331
  * CVE-2026-11605
  * CVE-2026-11622
  * CVE-2026-11721
  * CVE-2026-12617
  * CVE-2026-13204
  * CVE-2026-13321

  
CVSS scores:

  * CVE-2026-10723 ( SUSE ):  8.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
  * CVE-2026-10723 ( SUSE ):  6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
  * CVE-2026-10723 ( NVD ):  6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
  * CVE-2026-10822 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-10822 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-10822 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-11331 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11331 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-11331 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-11605 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-11605 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11605 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11622 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-11622 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11622 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11721 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11721 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11721 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-12617 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-12617 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-12617 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-13204 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-13204 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-13204 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-13321 ( SUSE ):  9.2
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
  * CVE-2026-13321 ( SUSE ):  8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
  * CVE-2026-13321 ( NVD ):  8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

  
Affected Products:

  * Basesystem Module 15-SP7
  * Server Applications Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves nine vulnerabilities can now be installed.

## Description:

This update for bind fixes the following issues:

Upgrade to release 9.20.26.

Security issues fixed:

  * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
  * CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected
    exit (bsc#1271983).
  * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
  * CVE-2026-11605: unnecessary validation of DNSSEC signed records
    (bsc#1271985).
  * CVE-2026-11622: potential memory usage beyond configured limits
    (bsc#1271986).
  * CVE-2026-11721: cache poisoning possible with label count discrepancy,
    RRSIG, and wildcards (bsc#1271987).
  * CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME
    (bsc#1271988).
  * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
    both present (bsc#1271989).
  * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
    (bsc#1271990).

Other updates and bugfixes:

  * Release 9.20.26:
  * Reclaim memory promptly when DNSSEC validations are canceled.
  * Removed Features:
    * Remove the secondary validator in query.c.
    * Remove ineffective TCP fallback after repeated UDP timeouts.
  * Feature Changes:
    * Fall back to TCP on receipt of a UDP response with a mismatched query ID.
    * Limit the number of glue records cached from a referral.
    * Fix a resolver stall on a CNAME response to a DS query.
  * Bug Fixes:
    * Fix a bug in DNS UPDATE processing with inline-signing enabled.
    * Properly detect private records before copying.
    * Tighten referral DS acceptance.
    * Don't synthesize negative responses with pending NSEC.
    * Check that an NSEC signer is at or above the name to be validated.
    * Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN.
    * Fix a deny-answer-aliases configuration bypass issue.
    * Reject external referrals from forwarders.
    * Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode.
    * Unvalidated opt-out NSEC3 could be accepted in insecurity proof.
    * Check wildcard signer and NOQNAME signer match.
    * Fix CNAME resolution failure caused by a cached SERVFAIL response.
    * Reject unsupported RSA DNSKEY shapes during DNSSEC validation.
    * Fix a bug in GeoIP2 string matching.
    * Fix DNS-over-HTTPS (DoH) quota configuration issue.
    * Truncated reply to a TSIG query no longer stalls the resolver.
    * Ignore updates removing DNSKEY RRset with class ANY.
    * Ignore 0-byte reads in the TCP read callback.
    * Only print per-zone glue stats when zone-statistics is set to full.
    * CDS/CDNSKEY records were not removed when re-configuring the server.
    * Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB.
    * Stop reusing outgoing TCP connections the peer has already closed.
    * Fix DNSSEC validation failures for names under an apex DNAME.
    * The resolver now removes other RRsets at the same name when caching a CNAME.
    * Fix nxdomain-redirect combined with dns64.
    * Fix DNS64 owner case after DNAME restart.
    * Clear REDIRECT flag when it isn't needed.
    * Disable output escaping in bind9.xsl.
    * Fix crash on badly configured secondary signer.
    * Fix a possible crash on concurrent TKEY DELETE for the same key.
    * Reject RRSIG records covering meta-types.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3426=1

  * Server Applications Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3426=1

## Package List:

  * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * bind-utils-9.20.26-150700.3.29.1
    * bind-debugsource-9.20.26-150700.3.29.1
    * bind-utils-debuginfo-9.20.26-150700.3.29.1
    * bind-debuginfo-9.20.26-150700.3.29.1
  * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * bind-debuginfo-9.20.26-150700.3.29.1
    * bind-debugsource-9.20.26-150700.3.29.1
    * bind-9.20.26-150700.3.29.1
  * Server Applications Module 15-SP7 (noarch)
    * bind-doc-9.20.26-150700.3.29.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-10723.html
  * https://www.suse.com/security/cve/CVE-2026-10822.html
  * https://www.suse.com/security/cve/CVE-2026-11331.html
  * https://www.suse.com/security/cve/CVE-2026-11605.html
  * https://www.suse.com/security/cve/CVE-2026-11622.html
  * https://www.suse.com/security/cve/CVE-2026-11721.html
  * https://www.suse.com/security/cve/CVE-2026-12617.html
  * https://www.suse.com/security/cve/CVE-2026-13204.html
  * https://www.suse.com/security/cve/CVE-2026-13321.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1271982
  * https://bugzilla.suse.com/show_bug.cgi?id=1271983
  * https://bugzilla.suse.com/show_bug.cgi?id=1271984
  * https://bugzilla.suse.com/show_bug.cgi?id=1271985
  * https://bugzilla.suse.com/show_bug.cgi?id=1271986
  * https://bugzilla.suse.com/show_bug.cgi?id=1271987
  * https://bugzilla.suse.com/show_bug.cgi?id=1271988
  * https://bugzilla.suse.com/show_bug.cgi?id=1271989
  * https://bugzilla.suse.com/show_bug.cgi?id=1271990

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260730/9b6d8caa/attachment.htm>


More information about the sle-updates mailing list