{"id":"SUSE-SU-2026:21204-1","summary":"Security update for bind","details":"This update for bind fixes the following issues:\n\n- Update to release 9.20.21\n- CVE-2026-1519: maliciously crafted DNSSEC-validated zone can lead to denial of service (bsc#1260805).\n- CVE-2026-3104: memory leak in code preparing DNSSEC proofs of non-existence allows for DoS (bsc#1260567).\n- CVE-2026-3119: authenticated queries containing a TKEY record may cause `named` to terminate unexpectedly (bsc#1260568).\n- CVE-2026-3591: stack use-after-return flaw in SIG(0) handling code allows for ACL bypass (bsc#1260569).\n","modified":"2026-04-22T18:25:45.941168Z","published":"2026-04-16T10:19:52Z","related":["CVE-2026-1519","CVE-2026-3104","CVE-2026-3119","CVE-2026-3591"],"upstream":["CVE-2026-1519","CVE-2026-3104","CVE-2026-3119","CVE-2026-3591"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621204-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260567"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260568"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260569"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260805"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3591"}],"affected":[{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.20.21-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"bind-modules-ldap":"9.20.21-160000.1.1","bind-modules-mysql":"9.20.21-160000.1.1","bind-modules-perl":"9.20.21-160000.1.1","bind-modules-sqlite3":"9.20.21-160000.1.1","bind-utils":"9.20.21-160000.1.1","bind":"9.20.21-160000.1.1","bind-doc":"9.20.21-160000.1.1","bind-modules-generic":"9.20.21-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21204-1.json"}},{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.20.21-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"bind-modules-generic":"9.20.21-160000.1.1","bind-modules-ldap":"9.20.21-160000.1.1","bind-modules-mysql":"9.20.21-160000.1.1","bind-modules-perl":"9.20.21-160000.1.1","bind-modules-sqlite3":"9.20.21-160000.1.1","bind-utils":"9.20.21-160000.1.1","bind":"9.20.21-160000.1.1","bind-doc":"9.20.21-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21204-1.json"}}],"schema_version":"1.7.5"}