{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0422",
  "published": "2026-09-20T04:25:32Z",
  "modified": "2026-09-20T02:48:26Z",
  "summary": "Updated bind package fixes security vulnerabilities",
  "details": "Unauthenticated IXFR deltas are applied to the live zone before TSIG\nverification (CVE-2026-19033).\nqpcache NOQNAME proof use-after-free crashes recursive resolver\n(CVE-2026-19662).\nUse-after-free in query_addnoqnameproof() via the DNS64 filter64 path\n(CVE-2026-19666).\nRemote assertion failure via 16-bit length truncation in\ndns_ncache_add() (CVE-2026-19667).\nResource Exhaustion via Excessive DNSSEC Cryptographic Material Matching\n(CVE-2026-19668).\ncheckwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence\nproof (CVE-2026-19941).\nMessage parser retains every identical singleton RDATA, enabling\nwire-to-work amplification (CVE-2026-75029).\nnamed aborts on a TKEY query when the user configuration has no global\noptions statement (CVE-2026-76163).\nNSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets\n(CVE-2026-77119).\nUnauthenticated remote crash of named via a single DoH SIG(0) request\n(CVE-2026-77692).\nOut-of-zone database nodes can become authoritative zone cuts\n(CVE-2026-78301).\nValidating resolver can abort while caching a mismatched NOQNAME proof\n(CVE-2026-80274).\nSVCB AliasMode additional-data error leaks qpcache references\n(CVE-2026-81563).\nRemote CPU denial of service through cached SVCB/HTTPS AliasMode trees\n(CVE-2026-81736).\n",
  "upstream": [
    "CVE-2026-19033",
    "CVE-2026-19662",
    "CVE-2026-19666",
    "CVE-2026-19667",
    "CVE-2026-19668",
    "CVE-2026-19941",
    "CVE-2026-75029",
    "CVE-2026-76163",
    "CVE-2026-77119",
    "CVE-2026-77692",
    "CVE-2026-78301",
    "CVE-2026-80274",
    "CVE-2026-81563",
    "CVE-2026-81736"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0422.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36326"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-19033"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-19662"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-19666"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-19667"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-19668"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-19941"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-75029"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-76163"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-77119"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-77692"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-78301"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-80274"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-81563"
    },
    {
      "type": "WEB",
      "url": "https://kb.isc.org/docs/cve-2026-81736"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "bind",
        "purl": "pkg:rpm/mageia/bind?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "9.20.29-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
