From null at suse.de Thu Aug 6 16:34:07 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 06 Aug 2026 16:34:07 -0000 Subject: SUSE-SU-2026:3517-1: important: Security update for bind Message-ID: <178603404714.242.3978712978930507641@70aaff0f9d46> # Security update for bind Announcement ID: SUSE-SU-2026:3517-1 Release Date: 2026-08-06T11:20:17Z Rating: important References: * bsc#1207471 * bsc#1265591 * bsc#1265592 * bsc#1265594 * bsc#1271982 * bsc#1271984 * bsc#1271986 * bsc#1271987 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2022-3094 * CVE-2026-10723 * CVE-2026-11331 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-13204 * CVE-2026-13321 * CVE-2026-3039 * CVE-2026-3592 * CVE-2026-5946 CVSS scores: * CVE-2022-3094 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-3039 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3592 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-3592 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Manager Client Tools for SLE Micro 5 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2022-3094: UPDATE message flood may cause `named` to exhaust all available memory (bsc#1207471). * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: invalid handling of `CLASS != IN` (bsc#1265594). * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2026-3517=1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-3517=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * bind-debugsource-9.16.6-150000.12.91.1 * bind-debuginfo-9.16.6-150000.12.91.1 * libisccc1600-debuginfo-9.16.6-150000.12.91.1 * libbind9-1600-debuginfo-9.16.6-150000.12.91.1 * libisc1606-debuginfo-9.16.6-150000.12.91.1 * libisccc1600-9.16.6-150000.12.91.1 * libisccfg1600-9.16.6-150000.12.91.1 * libirs1601-9.16.6-150000.12.91.1 * libdns1605-9.16.6-150000.12.91.1 * libisccfg1600-debuginfo-9.16.6-150000.12.91.1 * libbind9-1600-9.16.6-150000.12.91.1 * libns1604-debuginfo-9.16.6-150000.12.91.1 * bind-utils-9.16.6-150000.12.91.1 * libns1604-9.16.6-150000.12.91.1 * libdns1605-debuginfo-9.16.6-150000.12.91.1 * bind-utils-debuginfo-9.16.6-150000.12.91.1 * libirs1601-debuginfo-9.16.6-150000.12.91.1 * libisc1606-9.16.6-150000.12.91.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.91.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64 s390x x86_64) * libisccc1600-9.16.6-150000.12.91.1 * libdns1605-9.16.6-150000.12.91.1 * libisccfg1600-9.16.6-150000.12.91.1 * libirs1601-9.16.6-150000.12.91.1 * libns1604-debuginfo-9.16.6-150000.12.91.1 * libbind9-1600-9.16.6-150000.12.91.1 * bind-utils-9.16.6-150000.12.91.1 * libns1604-9.16.6-150000.12.91.1 * libisc1606-9.16.6-150000.12.91.1 * SUSE Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.91.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64_ilp32) * libisccfg1600-64bit-9.16.6-150000.12.91.1 * libirs1601-64bit-9.16.6-150000.12.91.1 * libisccc1600-64bit-9.16.6-150000.12.91.1 * libbind9-1600-64bit-9.16.6-150000.12.91.1 * libdns1605-64bit-9.16.6-150000.12.91.1 * libisc1606-64bit-9.16.6-150000.12.91.1 ## References: * https://www.suse.com/security/cve/CVE-2022-3094.html * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://www.suse.com/security/cve/CVE-2026-3039.html * https://www.suse.com/security/cve/CVE-2026-3592.html * https://www.suse.com/security/cve/CVE-2026-5946.html * https://bugzilla.suse.com/show_bug.cgi?id=1207471 * https://bugzilla.suse.com/show_bug.cgi?id=1265591 * https://bugzilla.suse.com/show_bug.cgi?id=1265592 * https://bugzilla.suse.com/show_bug.cgi?id=1265594 * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: