{"id":"SUSE-SU-2026:3452-1","summary":"Security update for bind","details":"This update for bind fixes the following issues:\n\n- CVE-2026-10723: accepting incorrect child-zone NSEC3 records as valid can allow an attacker to forge authenticated\n  NXDOMAIN responses for sibling zones (bsc#1271982).\n- CVE-2026-10822: storing a DNS key record with an invalid PRIVATEDNS algorithm identifier length can trigger a\n  consistency check failure (bsc#1271983).\n- CVE-2026-11331: handling NAMETOOLONG error conditions incorrectly during RPZ wildcard CNAME processing can allow\n  bypassing RPZ rules or triggering process exits (bsc#1271984).\n- CVE-2026-11622: DNSSEC validating resolver under a random subdomain attack can suffer from runaway memory usage\n  exceeding max-cache-size and affecting response rate (bsc#1271986).\n- CVE-2026-11721: RRSIG with fewer labels than its containing zone when synth-from-dnssec is enabled can lead to\n  wildcard generation (bsc#1271987).\n- CVE-2026-12617: delayed or specific CNAME/DNAME query responses combined with positive A record responses can trigger\n  an assertion failure (bsc#1271988).\n- CVE-2026-13204: validating a domain covered by both NSEC and NSEC3 with an RRSIG for only one type can trigger an\n  assertion failure (bsc#1271989).\n- CVE-2026-13321: NSEC records with a `Next Domain Name` pointing outside the signer's zone can allow cross-zone cache\n  poisoning and authenticated denial-of-service responses (bsc#1271990).\n\n- Update to release 9.18.50:\n\n * Remove ineffective TCP fallback after repeated UDP timeouts.\n * Fall back to TCP on receipt of a UDP response with a mismatched query ID.\n * Fix DNS64 owner case after DNAME restart.\n * Clear REDIRECT flag when it isn't needed.\n","modified":"2026-08-04T11:45:06.336072676Z","published":"2026-08-03T11:34:55Z","related":["CVE-2026-10723","CVE-2026-10822","CVE-2026-11331","CVE-2026-11622","CVE-2026-11721","CVE-2026-12617","CVE-2026-13204","CVE-2026-13321"],"upstream":["CVE-2026-10723","CVE-2026-10822","CVE-2026-11331","CVE-2026-11622","CVE-2026-11721","CVE-2026-12617","CVE-2026-13204","CVE-2026-13321"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263452-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271982"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271983"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271984"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271986"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271987"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271988"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271989"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10723"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10822"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13321"}],"affected":[{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.18.50-150600.3.32.1"}]}],"ecosystem_specific":{"binaries":[{"bind":"9.18.50-150600.3.32.1","bind-doc":"9.18.50-150600.3.32.1","bind-utils":"9.18.50-150600.3.32.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3452-1.json"}},{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.18.50-150600.3.32.1"}]}],"ecosystem_specific":{"binaries":[{"bind":"9.18.50-150600.3.32.1","bind-doc":"9.18.50-150600.3.32.1","bind-utils":"9.18.50-150600.3.32.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3452-1.json"}}],"schema_version":"1.8.0"}