SUSE-SU-2026:3426-1: important: Security update for bind
SLE-UPDATES
null at suse.de
Thu Jul 30 16:33:50 UTC 2026
# Security update for bind
Announcement ID: SUSE-SU-2026:3426-1
Release Date: 2026-07-30T11:12:13Z
Rating: important
References:
* bsc#1271982
* bsc#1271983
* bsc#1271984
* bsc#1271985
* bsc#1271986
* bsc#1271987
* bsc#1271988
* bsc#1271989
* bsc#1271990
Cross-References:
* CVE-2026-10723
* CVE-2026-10822
* CVE-2026-11331
* CVE-2026-11605
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-12617
* CVE-2026-13204
* CVE-2026-13321
CVSS scores:
* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10822 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-10822 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-10822 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11605 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11605 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-12617 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-12617 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-12617 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products:
* Basesystem Module 15-SP7
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves nine vulnerabilities can now be installed.
## Description:
This update for bind fixes the following issues:
Upgrade to release 9.20.26.
Security issues fixed:
* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected
exit (bsc#1271983).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11605: unnecessary validation of DNSSEC signed records
(bsc#1271985).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME
(bsc#1271988).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).
Other updates and bugfixes:
* Release 9.20.26:
* Reclaim memory promptly when DNSSEC validations are canceled.
* Removed Features:
* Remove the secondary validator in query.c.
* Remove ineffective TCP fallback after repeated UDP timeouts.
* Feature Changes:
* Fall back to TCP on receipt of a UDP response with a mismatched query ID.
* Limit the number of glue records cached from a referral.
* Fix a resolver stall on a CNAME response to a DS query.
* Bug Fixes:
* Fix a bug in DNS UPDATE processing with inline-signing enabled.
* Properly detect private records before copying.
* Tighten referral DS acceptance.
* Don't synthesize negative responses with pending NSEC.
* Check that an NSEC signer is at or above the name to be validated.
* Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN.
* Fix a deny-answer-aliases configuration bypass issue.
* Reject external referrals from forwarders.
* Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode.
* Unvalidated opt-out NSEC3 could be accepted in insecurity proof.
* Check wildcard signer and NOQNAME signer match.
* Fix CNAME resolution failure caused by a cached SERVFAIL response.
* Reject unsupported RSA DNSKEY shapes during DNSSEC validation.
* Fix a bug in GeoIP2 string matching.
* Fix DNS-over-HTTPS (DoH) quota configuration issue.
* Truncated reply to a TSIG query no longer stalls the resolver.
* Ignore updates removing DNSKEY RRset with class ANY.
* Ignore 0-byte reads in the TCP read callback.
* Only print per-zone glue stats when zone-statistics is set to full.
* CDS/CDNSKEY records were not removed when re-configuring the server.
* Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB.
* Stop reusing outgoing TCP connections the peer has already closed.
* Fix DNSSEC validation failures for names under an apex DNAME.
* The resolver now removes other RRsets at the same name when caching a CNAME.
* Fix nxdomain-redirect combined with dns64.
* Fix DNS64 owner case after DNAME restart.
* Clear REDIRECT flag when it isn't needed.
* Disable output escaping in bind9.xsl.
* Fix crash on badly configured secondary signer.
* Fix a possible crash on concurrent TKEY DELETE for the same key.
* Reject RRSIG records covering meta-types.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3426=1
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3426=1
## Package List:
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* bind-utils-9.20.26-150700.3.29.1
* bind-debugsource-9.20.26-150700.3.29.1
* bind-utils-debuginfo-9.20.26-150700.3.29.1
* bind-debuginfo-9.20.26-150700.3.29.1
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* bind-debuginfo-9.20.26-150700.3.29.1
* bind-debugsource-9.20.26-150700.3.29.1
* bind-9.20.26-150700.3.29.1
* Server Applications Module 15-SP7 (noarch)
* bind-doc-9.20.26-150700.3.29.1
## References:
* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-10822.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11605.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-12617.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id=1271982
* https://bugzilla.suse.com/show_bug.cgi?id=1271983
* https://bugzilla.suse.com/show_bug.cgi?id=1271984
* https://bugzilla.suse.com/show_bug.cgi?id=1271985
* https://bugzilla.suse.com/show_bug.cgi?id=1271986
* https://bugzilla.suse.com/show_bug.cgi?id=1271987
* https://bugzilla.suse.com/show_bug.cgi?id=1271988
* https://bugzilla.suse.com/show_bug.cgi?id=1271989
* https://bugzilla.suse.com/show_bug.cgi?id=1271990
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260730/9b6d8caa/attachment.htm>
More information about the sle-updates
mailing list