Advisories ยป MGASA-2026-0399

Updated bind package fixes a security vulnerability

Publication date: 13 Sep 2026
Modification date: 13 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-13204

Description

It was discovered that Bind incorrectly handled DNSSEC validation when a
domain was covered by both NSEC and NSEC3 records with only one type
having an RRSIG. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service (CVE-2026-13204).
                

References

SRPMS

9/core