{"id":"MGASA-2026-0331","summary":"Updated bind packages fix security vulnerabilities","details":"Updated bind packages fix security vulnerabilities:\nIncorrect acceptance of NSEC3 records. (CVE-2026-10723)\nKey Record using PRIVATEDNS algorithm may lead to unexpected exit.\n(CVE-2026-10822)\nPotential wildcard CNAME RPZ policy bypass. (CVE-2026-11331)\nUnnecessary validation of DNSSEC signed records. (CVE-2026-11605)\nCache poisoning possible with label count discrepancy, RRSIG, and\nwildcards. (CVE-2026-11721)\nRecord ordering based unexpected exit with CNAME or DNAME.\n(CVE-2026-12617)\nUnexpected exit in certain situations with NSEC and NSEC3 both present.\n(CVE-2026-13204)\nDNSSEC Validation Bypass via Out-of-Zone NSEC Next Field.\n(CVE-2026-13321)\n","modified":"2026-08-15T18:00:03.561699670Z","published":"2026-08-10T19:29:27Z","upstream":["CVE-2026-10723","CVE-2026-10822","CVE-2026-11331","CVE-2026-11605","CVE-2026-11721","CVE-2026-12617","CVE-2026-13204","CVE-2026-13321"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0331.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36003"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/07/22/8"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-10723"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-10822"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-11331"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-11605"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-11622"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-11721"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-12617"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-13204"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-13321"}],"affected":[{"package":{"name":"bind","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/bind?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.20.26-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0331.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}