{"id":"OESA-2026-4190","summary":"bind security update","details":"Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.\r\n\r\nSecurity Fix(es):\n\nIf a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-80274)","modified":"2026-10-01T02:00:06.772501572Z","published":"2026-09-30T13:47:27Z","upstream":["CVE-2026-80274"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4190"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80274"}],"affected":[{"package":{"name":"bind","ecosystem":"openEuler:22.03-LTS-SP4","purl":"pkg:rpm/openEuler/bind&distro=openEuler-22.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.16.23-32.oe2203sp4"}]}],"ecosystem_specific":{"aarch64":["bind-9.16.23-32.oe2203sp4.aarch64.rpm","bind-chroot-9.16.23-32.oe2203sp4.aarch64.rpm","bind-debuginfo-9.16.23-32.oe2203sp4.aarch64.rpm","bind-debugsource-9.16.23-32.oe2203sp4.aarch64.rpm","bind-devel-9.16.23-32.oe2203sp4.aarch64.rpm","bind-dnssec-utils-9.16.23-32.oe2203sp4.aarch64.rpm","bind-libs-9.16.23-32.oe2203sp4.aarch64.rpm","bind-pkcs11-9.16.23-32.oe2203sp4.aarch64.rpm","bind-pkcs11-devel-9.16.23-32.oe2203sp4.aarch64.rpm","bind-pkcs11-libs-9.16.23-32.oe2203sp4.aarch64.rpm","bind-pkcs11-utils-9.16.23-32.oe2203sp4.aarch64.rpm","bind-utils-9.16.23-32.oe2203sp4.aarch64.rpm"],"noarch":["bind-dnssec-doc-9.16.23-32.oe2203sp4.noarch.rpm","bind-license-9.16.23-32.oe2203sp4.noarch.rpm","python3-bind-9.16.23-32.oe2203sp4.noarch.rpm"],"src":["bind-9.16.23-32.oe2203sp4.src.rpm"],"x86_64":["bind-9.16.23-32.oe2203sp4.x86_64.rpm","bind-chroot-9.16.23-32.oe2203sp4.x86_64.rpm","bind-debuginfo-9.16.23-32.oe2203sp4.x86_64.rpm","bind-debugsource-9.16.23-32.oe2203sp4.x86_64.rpm","bind-devel-9.16.23-32.oe2203sp4.x86_64.rpm","bind-dnssec-utils-9.16.23-32.oe2203sp4.x86_64.rpm","bind-libs-9.16.23-32.oe2203sp4.x86_64.rpm","bind-pkcs11-9.16.23-32.oe2203sp4.x86_64.rpm","bind-pkcs11-devel-9.16.23-32.oe2203sp4.x86_64.rpm","bind-pkcs11-libs-9.16.23-32.oe2203sp4.x86_64.rpm","bind-pkcs11-utils-9.16.23-32.oe2203sp4.x86_64.rpm","bind-utils-9.16.23-32.oe2203sp4.x86_64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-4190.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}