{"id":"MGASA-2026-0422","summary":"Updated bind package fixes security vulnerabilities","details":"Unauthenticated IXFR deltas are applied to the live zone before TSIG\nverification (CVE-2026-19033).\nqpcache NOQNAME proof use-after-free crashes recursive resolver\n(CVE-2026-19662).\nUse-after-free in query_addnoqnameproof() via the DNS64 filter64 path\n(CVE-2026-19666).\nRemote assertion failure via 16-bit length truncation in\ndns_ncache_add() (CVE-2026-19667).\nResource Exhaustion via Excessive DNSSEC Cryptographic Material Matching\n(CVE-2026-19668).\ncheckwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence\nproof (CVE-2026-19941).\nMessage parser retains every identical singleton RDATA, enabling\nwire-to-work amplification (CVE-2026-75029).\nnamed aborts on a TKEY query when the user configuration has no global\noptions statement (CVE-2026-76163).\nNSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets\n(CVE-2026-77119).\nUnauthenticated remote crash of named via a single DoH SIG(0) request\n(CVE-2026-77692).\nOut-of-zone database nodes can become authoritative zone cuts\n(CVE-2026-78301).\nValidating resolver can abort while caching a mismatched NOQNAME proof\n(CVE-2026-80274).\nSVCB AliasMode additional-data error leaks qpcache references\n(CVE-2026-81563).\nRemote CPU denial of service through cached SVCB/HTTPS AliasMode trees\n(CVE-2026-81736).\n","modified":"2026-09-20T04:30:03.399621511Z","published":"2026-09-20T04:25:32Z","upstream":["CVE-2026-19033","CVE-2026-19662","CVE-2026-19666","CVE-2026-19667","CVE-2026-19668","CVE-2026-19941","CVE-2026-75029","CVE-2026-76163","CVE-2026-77119","CVE-2026-77692","CVE-2026-78301","CVE-2026-80274","CVE-2026-81563","CVE-2026-81736"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0422.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36326"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-19033"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-19662"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-19666"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-19667"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-19668"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-19941"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-75029"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-76163"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-77119"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-77692"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-78301"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-80274"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-81563"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2026-81736"}],"affected":[{"package":{"name":"bind","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/bind?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.20.29-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0422.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}