[9.18] [CVE-2026-13321] sec: usr: Fix DNSSEC validation bypass via out-of-zone NSEC Next Field
A malicious zone with out-of-zone NSEC next owner names can cause a DNSSEC validating resolver to cache such record and, if `synth-from-dnssec` is enabled, to generate negative answers for any zone that is covered by the range.
ISC would like to thank Qifan Zhang of Palo Alto Networks for reporting the issue.
Closesisc-projects/bind9#5873
[9.18] [CVE-2026-13204] fix: usr: Prevent crash from malformed NSEC/NSEC3 response
An assertion could be triggered by an improperly signed NOQNAME proof. This has been fixed.
ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue.
Closes https://gitlab.isc.org/isc-projects/bind9/-/issues/5985
[9.18] [CVE-2026-10723] sec: usr: Correct verification of NSEC3 signer name
BIND 9 accepted child-zone NSEC3 records where the first label equals the hash of the parent zone as valid parent-zone closest encloser proofs. This has been fixed.
ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue.
Closesisc-projects/bind9#5874
[9.18] [CVE-2026-11721] sec: usr: Invalid signed wildcard records were being accepted
Signed wildcard responses in which the Labels field in the `RRSIG` record was less than the number of labels in the Signer Name field were being incorrectly accepted. This in turn broke `synth-from-dnssec`, which depends on such records being correctly validated. This has been fixed.
ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention.
Closes https://gitlab.isc.org/isc-projects/bind9/-/issues/5871
[9.18] [CVE-2026-11622] sec: usr: Prevent cache exhaustion under sustained attack
The cache memory can become exhausted with expired entries whose memory
is not released due to a sustained attack on the same DNS name that
prevents the cleanup. This has been fixed.
Closes: https://gitlab.isc.org/isc-projects/bind9/-/work_items/4760
[9.18] [CVE-2026-12617] sec: usr: Do no assert for some specifics CNAME and DNAME queries
A bug in the resolver's handling of certain cached DNAME and CNAME responses could cause named to trigger an assertion failure and exit. An attacker controlling a domain name and the authoritative DNS server it is hosted on could exploit this behavior to cause a denial-of-service. This vulnerability has been fixed.
ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention.
Closes: isc-projects/bind9#5946
[9.18] fix: test: Stabilize the cname_dname_negcache test
The test proved unstable due to timing-related race condition, which could produce both false positive and false negative results. Use a more reliable mechanism to reproduce the issue.
Human-effort-level: low
[9.18] [CVE-2026-10822] sec: usr: Fix dns_name_fromwire to record boundaries
Previously, `dns_name_fromwire()` did not honor the record boundary when reading names from the wire, allowing malformed records to be accepted when they should not have been. This has been fixed.
Closes: https://gitlab.isc.org/isc-projects/bind9/-/issues/6004
[9.18] [CVE-2026-11331] sec: usr: Fix handling of rpz CNAME expansion that returns name too long
Previously, if the expansion of a wildcard CNAME RPZ policy resulted in a name that exceeded the length limit, a self referential CNAME and the original address record were returned, allowing the policy to be bypassed. In branches up to 9.20, this also left query processing in an inconsistent state which could trigger an assertion failure. We now return a YXDOMAIN response, without the address.
ISC would like to thank Laith Mash'al (0xmshal) for bringing this issue to our attention.
Closes https://gitlab.isc.org/isc-projects/bind9/-/issues/5856
Removed Features:
- Remove ineffective TCP fallback after repeated UDP timeouts.
Feature Changes:
- Fall back to TCP on receipt of a UDP response with a mismatched query ID.
Bug Fixes:
- Fix DNS64 owner case after DNAME restart.
- Clear REDIRECT flag when it isn't needed.
This should be final release of BIND 9.18 line. That version is now
marked EOL.
Source: https://downloads.isc.org/isc/bind9/9.18.50/doc/arm/html/notes.html#notes-for-bind-9-18-50
Security Fixes:
- Limit resolver server list size. (CVE-2026-3592)
- Fix GSS-API resource leak. (CVE-2026-3039)
- Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)
- Avoid unbounded recursion loop. (CVE-2026-5950)
- Fix outgoing zone transfers' quota issue.
Feature Changes:
- Fix CPU spikes and slow queries when cache approaches memory limit.
Bug Fixes:
- Fix named crash when processing SIG records in dynamic updates.
- Fix rndc modzone behavior for a zone in named.conf.
- Fix zone verification of NSEC3 signed zones.
- Prevent a crash when using both dns64 and filter-aaaa.
- Fixed an assertion failure when processing catalog zones.
- Prevent malicious DNSSEC zones from exhausting validator CPU.
- Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits.
- Prevent crafted queries from degrading RRL performance.
- Fix a bug in allow-query/allow-transfer catalog zone custom properties.
- Fix a memory leak issue in catalog zones.
- Fix suppressed missing-glue check in named-checkzone.
- Reject record sets too large to serve in DNS.
Source: https://downloads.isc.org/isc/bind9/9.18.49/doc/arm/html/notes.html#notes-for-bind-9-18-49
One of libdir directories was forgotten. It is the directory containing
the actual plugin, might cause issues if filter-aaaa.so plugin is used.
Related: RHEL-132054
Security fixes:
- DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677)
- Address various spoofing attacks. (CVE-2025-40778)
- Cache-poisoning due to weak pseudo-random number generator.
(CVE-2025-40780)
New Features:
- Support for parsing HHIT and BRID records has been added.
Removed Features:
- Deprecate the "tkey-domain" statement.
- Deprecate the "tkey-gssapi-credential" statement.
Bug Fixes:
- Prevent spurious SERVFAILs for certain 0-TTL resource records.
- Missing DNSSEC information when CD bit is set in query.
https://downloads.isc.org/isc/bind9/9.18.41/doc/arm/html/notes.html#notes-for-bind-9-18-41
Make the reference to primary source in absolute path, rather than
relative to working directory.
Potentially could start using different files than it used before.
Dot not cherry-pick this into stable branches. Could be considered
breaking change, keep it just in rawhide only.
Imagemode might have separate /var partition not properly initialized by
package installation. Add creation of compat files into tmpfiles.d
definition.
Move primary place of those files from /var/named to /usr/shared/named, so we
even have some place to symlink them from. Originally it had only copy
in sample documentation, which may not be installed.
These source file should be read-only from named and not modified
anyway. Move them to /usr/share/named as read-only, always present
sources. Change compat symlinks in /var/named to point to them instead
of /etc.
Make the doc files only symlinks to those files too, have them there
just once.
Keep named.ca config file in /etc/named.ca
The rest can stay in _datadir, but named.ca can be potentially updated
and as such should remain in /etc and its modification kept.
Move primary copy into /etc and keep just legacy symlink inside
/var/named. Configuration should stay working if the file were modified.
Related: RHEL-97443
IDNA tests always redirect output into the file. That means its
behaviour has changed and is now processing IDN input by default and
just disables IDN output by default.
New behaviour when redirected is the same as +idnin +noidnout, but does
not fail hard on input errors.
Related: RHEL-112765
Resolves: rhbz#2324186
Many variants are never built anymore. Clean actions to just those still
shipped. But do not trigger named reload when named.run file is empty.
That is common on freeipa installation, where configuration changes
logging to put it elsewhere. named reload is disruptive because how
bind-dyndb-ldap behaves during reloads. Avoid unnecessary reloads with
visible service disruption.
Use the same name in dig or host utilities when stdout is not a
terminal. Until now it disabled IDN processing when stdout were not a
terminal. Disable just IDN output in that case and try to decode input
name with IDN. Keep failing in interactive sessions, but send even
undecoded name query when output is redirected.
That should limit new surprises and keep most of behaviour without
changes. But do not break in when input name failed to decode and
it were not trying to decode it before.
Related: RHEL-66172
New Features:
- Support for parsing the DSYNC record has been added.
Feature Changes:
- Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1, and DS digest type 1.
Bug Fixes:
- Clean enough memory when adding new ADB names/entries under memory pressure.
- Rescan the interfaces again when reconfiguring the server.
https://downloads.isc.org/isc/bind9/9.18.39/doc/arm/html/notes.html#notes-for-bind-9-18-39
Security Fixes:
- Fix an issue when some specific queries could remain unanswered with serve-stale enabled.
New Features:
- Add support for the CO flag to dig.
Bug fixes:
- Correct the default interface-interval from 60s to 60m.
- Fix a purge-keys bug when using multiple views of a zone.
resume_qmin did not handle special case of recursing query hit
unexpected DNS_R_CNAME result. Change result to SERVFAIL in case
of a zone loaded after the recursion started. That prevents crashing
later in query_setorder, where there is uninitialized foundname compared
with absolute order names.
https://gitlab.isc.org/isc-projects/bind9/-/issues/5357
Related: RHEL-30407
Feature Changes:
- Make TLS data processing more reliable in various network conditions.
Bug Fixes:
- Stop caching lack of EDNS support
- Fix resolver statistics counters for timed-out responses.
- Don’t enforce NOAUTH/NOCONF flags in DNSKEYs.
- Fix inconsistency in CNAME/DNAME handling during resolution.
https://downloads.isc.org/isc/bind9/9.18.36/doc/arm/html/notes.html#notes-for-bind-9-18-36
Security Fixes:
- DNS-over-HTTPS flooding fixes. (CVE-2024-12705)
- Limit additional section processing for large RDATA sets. (CVE-2024-11187)
New Features:
- Add a new option to configure the maximum number of outgoing queries per client request.
Bug Fixes:
- Fix nsupdate hang when processing a large update.
- Fix possible assertion failure when reloading server while processing update policy rules. [GL #5006]
- Fix dnssec-signzone signing non-DNSKEY RRsets with revoked keys.
- Fix improper handling of unknown directives in resolv.conf.
https://downloads.isc.org/isc/bind9/9.18.33/doc/arm/html/notes.html#notes-for-bind-9-18-33