ELA-1786-1 bind9 security update

multiple vulnerabilities

2026-07-27
Packagebind9
Version1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1 (buster)
Related CVEs CVE-2025-8677 CVE-2026-1519 CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-11622 CVE-2026-11721 CVE-2026-13204 CVE-2026-13321


Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in bypass of DNSSEC validation, RPZ policy bypass, cache poisoning or denial of service.



For Debian 10 buster, these problems have been fixed in version 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1.

We recommend that you upgrade your bind9 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.