SUSE-SU-2026:4285-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264285-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4285-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4285-1
Upstream
CVE (14)
  • CVE-2026-19033
  • CVE-2026-19662
  • CVE-2026-19666
  • CVE-2026-19667
  • CVE-2026-19668
  • CVE-2026-19941
  • CVE-2026-75029
  • CVE-2026-76163
  • CVE-2026-77119
  • CVE-2026-77692
  • CVE-2026-78301
  • CVE-2026-80274
  • CVE-2026-81563
  • CVE-2026-81736
Related
Published
2026-09-22T16:08:33Z
Modified
2026-09-23T09:15:05Z
Summary
Security update for bind
Details

This update for bind fixes the following issues:

  • CVE-2026-19033: Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (bsc#1280430).
  • CVE-2026-19662: qpcache NOQNAME proof use-after-free crashes recursive resolver (bsc#1280432).
  • CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (bsc#1280433).
  • CVE-2026-19667: Remote assertion failure via 16-bit length truncation in dns_ncache_add() (bsc#1280435).
  • CVE-2026-19668: Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (bsc#1280436).
  • CVE-2026-19941: checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (bsc#1280437).
  • CVE-2026-75029: Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (bsc#1280438).
  • CVE-2026-76163: named aborts on a TKEY query when the user configuration has no global options statement (bsc#1280439).
  • CVE-2026-77119: NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (bsc#1280440).
  • CVE-2026-77692: Unauthenticated remote crash of named via a single DoH SIG(0) request (bsc#1280441).
  • CVE-2026-78301: Out-of-zone database nodes can become authoritative zone cuts (bsc#1280442).
  • CVE-2026-80274: Validating resolver can abort while caching a mismatched NOQNAME proof (bsc#1280443).
  • CVE-2026-81563: SVCB AliasMode additional-data error leaks qpcache references (bsc#1280444).
  • CVE-2026-81736: Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (bsc#1280445).

Changes for bind:

Upgrade to release 9.20.29

New Features:

  • Disclose active Negative Trust Anchors with Extended DNS Error

Feature Changes:

  • Reject oversized and malformed DNSKEY records up front.
  • Speed up RPZ policy zone updates. Bug Fixes:
  • Prevent a crash when using both dns64 and filter-a.
  • Stop passing UDP client addresses to update-policy external helpers.
  • Missing required NSEC3 for delegation not detected.
  • Tighten EUI48 and EUI64 text parsing.
  • GeoIP ACL state could be stale or wrong after reload.
  • Honor DNSSEC policy key tag ranges.
  • Fix a double free in mdig when EDNS options are specified.
  • Fix a crash when an IXFR falls back to AXFR with updates still pending.
  • Fix DS requests to parental agents over TLS.
  • Fix the rndc-confgen -q (quiet) option.
  • Enforce query ACLs for redirect zones and searched DLZs.
  • Check asnum validity in GeoIP ACLs.
  • Fix a crash on remote-servers lists that reference themselves.
  • A record from outside a response policy zone could crash named.
  • Invalid key-store configuration could abort the DNSSEC tools.
  • NSEC signature set could bypass the secure-delegation check.
  • Fix a possible nsupdate issue when using GSS-TSIG.
  • Fix a crash with a single-element geoip sortlist.
  • Prevent out-of-bailiwick CNAMEs from evicting cached records.
  • Restore periodic cleanup of stale resolver address data.
  • Fix named-checkconf/named crash with malformed key name.
  • Prevent resolver crashes while processing DNS over TCP.
  • Ensure NSEC authority does not cross zonecut boundary.
  • Treat an unusable NSEC3 chain as a verification failure.
  • Treat non-canonical RPZ prefixes as any other failure.
  • Negative caching stopped working with stale-answer-client-timeout set to 0.
  • An unterminated OpenSSL private-key Label: field could be read past its parser buffer.
  • Restore SMF support on Solaris and illumos.
  • Fix compilation on GNU/Hurd.
  • dig +yaml was producing invalid YAML when a lookup failed.
  • Properly prevent TSIG generation command line injection attacks.
  • Fix a potential heap bounds overflow write in dnssec-signzone.
  • Fix crashes on invalid DNSTAP input in dnstap-read.
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.20.29-150700.3.32.2

Ecosystem specific

{
    "binaries":  [
        {
            "bind-utils":  "9.20.29-150700.3.32.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4285-1.json"
SUSE:Linux Enterprise Module for Server Applications 15 SP7
bind

Package

Name
bind
Purl
pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.20.29-150700.3.32.2

Ecosystem specific

{
    "binaries":  [
        {
            "bind":  "9.20.29-150700.3.32.2",
            "bind-doc":  "9.20.29-150700.3.32.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4285-1.json"