{"id":"SUSE-SU-2026:4285-1","summary":"Security update for bind","details":"This update for bind fixes the following issues:\n\n- CVE-2026-19033: Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (bsc#1280430).\n- CVE-2026-19662: qpcache NOQNAME proof use-after-free crashes recursive resolver (bsc#1280432).\n- CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (bsc#1280433).\n- CVE-2026-19667: Remote assertion failure via 16-bit length truncation in dns_ncache_add() (bsc#1280435).\n- CVE-2026-19668: Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (bsc#1280436).\n- CVE-2026-19941: checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (bsc#1280437).\n- CVE-2026-75029: Message parser retains every identical singleton RDATA, enabling wire-to-work amplification\n  (bsc#1280438).\n- CVE-2026-76163: named aborts on a TKEY query when the user configuration has no global options statement\n  (bsc#1280439).\n- CVE-2026-77119: NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (bsc#1280440).\n- CVE-2026-77692: Unauthenticated remote crash of named via a single DoH SIG(0) request (bsc#1280441).\n- CVE-2026-78301: Out-of-zone database nodes can become authoritative zone cuts (bsc#1280442).\n- CVE-2026-80274: Validating resolver can abort while caching a mismatched NOQNAME proof (bsc#1280443).\n- CVE-2026-81563: SVCB AliasMode additional-data error leaks qpcache references (bsc#1280444).\n- CVE-2026-81736: Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (bsc#1280445).\n\nChanges for bind:\n\nUpgrade to release 9.20.29\n  \n New Features:\n * Disclose active Negative Trust Anchors with Extended DNS Error\n 33.\n Feature Changes:\n * Reject oversized and malformed DNSKEY records up front.\n * Speed up RPZ policy zone updates.\n Bug Fixes:\n * Prevent a crash when using both dns64 and filter-a.\n * Stop passing UDP client addresses to update-policy external\n helpers.\n * Missing required NSEC3 for delegation not detected.\n * Tighten EUI48 and EUI64 text parsing.\n * GeoIP ACL state could be stale or wrong after reload.\n * Honor DNSSEC policy key tag ranges.\n * Fix a double free in mdig when EDNS options are specified.\n * Fix a crash when an IXFR falls back to AXFR with updates still\n pending.\n * Fix DS requests to parental agents over TLS.\n * Fix the rndc-confgen -q (quiet) option.\n * Enforce query ACLs for redirect zones and searched DLZs.\n * Check asnum validity in GeoIP ACLs.\n * Fix a crash on remote-servers lists that reference themselves.\n * A record from outside a response policy zone could crash named.\n * Invalid key-store configuration could abort the DNSSEC tools.\n * NSEC signature set could bypass the secure-delegation check.\n * Fix a possible nsupdate issue when using GSS-TSIG.\n * Fix a crash with a single-element geoip sortlist.\n * Prevent out-of-bailiwick CNAMEs from evicting cached records.\n * Restore periodic cleanup of stale resolver address data.\n * Fix named-checkconf/named crash with malformed key name.\n * Prevent resolver crashes while processing DNS over TCP.\n * Ensure NSEC authority does not cross zonecut boundary.\n * Treat an unusable NSEC3 chain as a verification failure.\n * Treat non-canonical RPZ prefixes as any other failure.\n * Negative caching stopped working with\n stale-answer-client-timeout set to 0.\n * An unterminated OpenSSL private-key Label: field could be read\n past its parser buffer.\n * Restore SMF support on Solaris and illumos.\n * Fix compilation on GNU/Hurd.\n * dig +yaml was producing invalid YAML when a lookup failed.\n * Properly prevent TSIG generation command line injection\n attacks.\n * Fix a potential heap bounds overflow write in dnssec-signzone.\n * Fix crashes on invalid DNSTAP input in dnstap-read.\n","modified":"2026-09-23T09:15:05.374856931Z","published":"2026-09-22T16:08:33Z","related":["CVE-2026-19033","CVE-2026-19662","CVE-2026-19666","CVE-2026-19667","CVE-2026-19668","CVE-2026-19941","CVE-2026-75029","CVE-2026-76163","CVE-2026-77119","CVE-2026-77692","CVE-2026-78301","CVE-2026-80274","CVE-2026-81563","CVE-2026-81736"],"upstream":["CVE-2026-19033","CVE-2026-19662","CVE-2026-19666","CVE-2026-19667","CVE-2026-19668","CVE-2026-19941","CVE-2026-75029","CVE-2026-76163","CVE-2026-77119","CVE-2026-77692","CVE-2026-78301","CVE-2026-80274","CVE-2026-81563","CVE-2026-81736"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264285-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280432"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280433"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280435"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280436"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280437"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280438"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280439"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280440"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280442"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280443"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280444"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280445"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19667"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-77119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-77692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-80274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81563"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81736"}],"affected":[{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.20.29-150700.3.32.2"}]}],"ecosystem_specific":{"binaries":[{"bind-utils":"9.20.29-150700.3.32.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4285-1.json"}},{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.20.29-150700.3.32.2"}]}],"ecosystem_specific":{"binaries":[{"bind-doc":"9.20.29-150700.3.32.2","bind":"9.20.29-150700.3.32.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4285-1.json"}}],"schema_version":"1.9.0"}