ELA-1802-1 bind9 security update

multiple vulnerabilities

2026-08-12
Packagebind9
Version1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1~deb9u1 (stretch)
Related CVEs CVE-2023-4408 CVE-2025-8677 CVE-2025-40778 CVE-2026-1519 CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-11622 CVE-2026-11721 CVE-2026-13204 CVE-2026-13321


bind9 a popular name (DNS) server was affected by multiple vulnerabilities.

CVE-2023-4408

The DNS message parsing code in `named` includes a section whose computational complexity is overly high.
It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw

CVE-2025-8677

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.

CVE-2025-40778

BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.

CVE-2026-1519

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU.

CVE-2026-3039

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption
when receiving and processing maliciously-constructed packets.

CVE-2026-3592

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack.
If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources.

CVE-2026-5946

Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (`IN`),
for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section.

CVE-2026-5950

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling,
enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger
specific retry conditions.

CVE-2026-10723

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge
authenticated NXDOMAIN responses.

CVE-2026-11622

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage.

CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone
in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that
is shorter than the attacker's zone, which can result in cache poisoning.

CVE-2026-13204

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG
for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.

CVE-2026-13321

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.

BIND has been backported from buster to stretch in order to address these vulnerabilities, which entails a major version upgrade. Existing user configurations are expected to remain valid thanks to strong upstream forward‑compatibility.

However, this upgrade breaks binary compatibility. Third‑party applications linked against the BIND9 libraries may therefore require rebuilding.

To deliver the security fixes, several archive packages needed updates. The packages isc‑dhcp, libnss‑lwres, milter‑greylist, and bind‑dyndb‑ldap were rebuilt for stretch. Additionally, to maintain strictly increasing version numbers and ensure a smooth upgrade path, libnss‑lwres and milter‑greylist were also rebuilt for buster.



For Debian 9 stretch, these problems have been fixed in version 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1~deb9u1.

We recommend that you upgrade your bind9 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.