| Package | bind9 |
|---|---|
| Version | 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1~deb9u1 (stretch) |
| Related CVEs | CVE-2023-4408 CVE-2025-8677 CVE-2025-40778 CVE-2026-1519 CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-11622 CVE-2026-11721 CVE-2026-13204 CVE-2026-13321 |
bind9 a popular name (DNS) server was affected by multiple vulnerabilities.
CVE-2023-4408
The DNS message parsing code in `named` includes a section whose computational complexity is overly high.
It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw
CVE-2025-8677
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
CVE-2025-40778
BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
CVE-2026-1519
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU.
CVE-2026-3039
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption
when receiving and processing maliciously-constructed packets.
CVE-2026-3592
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack.
If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources.
CVE-2026-5946
Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (`IN`),
for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section.
CVE-2026-5950
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling,
enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger
specific retry conditions.
CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge
authenticated NXDOMAIN responses.
CVE-2026-11622
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage.
CVE-2026-11721
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone
in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that
is shorter than the attacker's zone, which can result in cache poisoning.
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG
for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
CVE-2026-13321
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.
BIND has been backported from buster to stretch in order to address these vulnerabilities, which entails a major version upgrade. Existing user configurations are expected to remain valid thanks to strong upstream forward‑compatibility.
However, this upgrade breaks binary compatibility. Third‑party applications linked against the BIND9 libraries may therefore require rebuilding.
To deliver the security fixes, several archive packages needed updates. The packages isc‑dhcp, libnss‑lwres, milter‑greylist, and bind‑dyndb‑ldap were rebuilt for stretch. Additionally, to maintain strictly increasing version numbers and ensure a smooth upgrade path, libnss‑lwres and milter‑greylist were also rebuilt for buster.
For Debian 9 stretch, these problems have been fixed in version 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1~deb9u1.
We recommend that you upgrade your bind9 packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.