{"id":"OESA-2026-3329","summary":"bind security update","details":"BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.\r\n\r\nSecurity Fix(es):\n\nA DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.(CVE-2026-11622)","modified":"2026-08-16T01:45:16.279909233Z","published":"2026-08-13T13:57:56Z","upstream":["CVE-2026-11622"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3329"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11622"}],"affected":[{"package":{"name":"bind","ecosystem":"openEuler:24.03-LTS-SP3","purl":"pkg:rpm/openEuler/bind&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.18.21-12.oe2403sp3"}]}],"ecosystem_specific":{"aarch64":["bind-9.18.21-12.oe2403sp3.aarch64.rpm","bind-chroot-9.18.21-12.oe2403sp3.aarch64.rpm","bind-debuginfo-9.18.21-12.oe2403sp3.aarch64.rpm","bind-debugsource-9.18.21-12.oe2403sp3.aarch64.rpm","bind-devel-9.18.21-12.oe2403sp3.aarch64.rpm","bind-dnssec-utils-9.18.21-12.oe2403sp3.aarch64.rpm","bind-libs-9.18.21-12.oe2403sp3.aarch64.rpm","bind-utils-9.18.21-12.oe2403sp3.aarch64.rpm"],"noarch":["bind-dnssec-doc-9.18.21-12.oe2403sp3.noarch.rpm","bind-license-9.18.21-12.oe2403sp3.noarch.rpm"],"src":["bind-9.18.21-12.oe2403sp3.src.rpm"],"x86_64":["bind-9.18.21-12.oe2403sp3.x86_64.rpm","bind-chroot-9.18.21-12.oe2403sp3.x86_64.rpm","bind-debuginfo-9.18.21-12.oe2403sp3.x86_64.rpm","bind-debugsource-9.18.21-12.oe2403sp3.x86_64.rpm","bind-devel-9.18.21-12.oe2403sp3.x86_64.rpm","bind-dnssec-utils-9.18.21-12.oe2403sp3.x86_64.rpm","bind-libs-9.18.21-12.oe2403sp3.x86_64.rpm","bind-utils-9.18.21-12.oe2403sp3.x86_64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3329.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}