Updated bind packages fix security vulnerabilities
Publication date: 10 Aug 2026Modification date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
Description
Updated bind packages fix security vulnerabilities:
Incorrect acceptance of NSEC3 records. (CVE-2026-10723)
Key Record using PRIVATEDNS algorithm may lead to unexpected exit.
(CVE-2026-10822)
Potential wildcard CNAME RPZ policy bypass. (CVE-2026-11331)
Unnecessary validation of DNSSEC signed records. (CVE-2026-11605)
Cache poisoning possible with label count discrepancy, RRSIG, and
wildcards. (CVE-2026-11721)
Record ordering based unexpected exit with CNAME or DNAME.
(CVE-2026-12617)
Unexpected exit in certain situations with NSEC and NSEC3 both present.
(CVE-2026-13204)
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field.
(CVE-2026-13321)
References
- https://bugs.mageia.org/show_bug.cgi?id=36003
- https://www.openwall.com/lists/oss-security/2026/07/22/8
- https://kb.isc.org/docs/cve-2026-10723
- https://kb.isc.org/docs/cve-2026-10822
- https://kb.isc.org/docs/cve-2026-11331
- https://kb.isc.org/docs/cve-2026-11605
- https://kb.isc.org/docs/cve-2026-11622
- https://kb.isc.org/docs/cve-2026-11721
- https://kb.isc.org/docs/cve-2026-12617
- https://kb.isc.org/docs/cve-2026-13204
- https://kb.isc.org/docs/cve-2026-13321
SRPMS
10/core
- bind-9.20.26-1.mga10