The bind rpms
  • C 44%
  • Shell 26.3%
  • Python 19.5%
  • Makefile 10.2%
Find a file
Petr Menšík a27e5daaca DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
[9.18] [CVE-2026-13321] sec: usr: Fix DNSSEC validation bypass via out-of-zone NSEC Next Field

A malicious zone with out-of-zone NSEC next owner names can cause a DNSSEC validating resolver to cache such record and, if `synth-from-dnssec` is enabled, to generate negative answers for any zone that is covered by the range.

ISC would like to thank Qifan Zhang of Palo Alto Networks for reporting the issue.

Closes isc-projects/bind9#5873
2026-08-25 14:51:41 +02:00
.fmf Adding fmf plan 2022-01-04 11:16:17 +01:00
plans fedora CI plans move to gitlab for centos-stream test space https://issues.redhat.com/browse/RHELMISC-13073 2025-06-12 16:09:36 +00:00
.gitignore Use common pattern in gitignore for every minor update 2025-02-10 16:33:43 +01:00
bind-9.5-PIE.patch Update to 9.18.32 (rhbz#2331675) 2024-12-12 20:58:44 +01:00
bind-9.11.12.tar.gz.asc fixup! Update to 9.11.12 (#1557762) 2019-10-21 15:44:10 +02:00
bind-9.14.7.tar.gz.asc Update to 9.14.7 2020-03-27 11:25:12 +01:00
bind-9.16-redhat_doc.patch Import version from branch v9_18 2022-08-03 20:37:06 +02:00
bind-9.18-CVE-2026-10723-test.patch Incorrect acceptance of NSEC3 records (CVE-2026-10723) 2026-08-25 14:50:47 +02:00
bind-9.18-CVE-2026-10723.patch Incorrect acceptance of NSEC3 records (CVE-2026-10723) 2026-08-25 14:50:47 +02:00
bind-9.18-CVE-2026-10822-test.patch Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822) 2026-08-25 14:48:54 +02:00
bind-9.18-CVE-2026-10822.patch Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822) 2026-08-25 14:48:54 +02:00
bind-9.18-CVE-2026-11331-test.patch Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) 2026-08-25 14:48:29 +02:00
bind-9.18-CVE-2026-11331.patch Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) 2026-08-25 14:48:29 +02:00
bind-9.18-CVE-2026-11622.patch Potential memory usage beyond configured limits (CVE-2026-11622) 2026-08-25 14:49:53 +02:00
bind-9.18-CVE-2026-11721-test.patch Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) 2026-08-25 14:50:24 +02:00
bind-9.18-CVE-2026-11721.patch Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) 2026-08-25 14:50:24 +02:00
bind-9.18-CVE-2026-12617-test.patch Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617) 2026-08-25 14:49:18 +02:00
bind-9.18-CVE-2026-12617.patch Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617) 2026-08-25 14:49:18 +02:00
bind-9.18-CVE-2026-13204-test.patch Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) 2026-08-25 14:51:13 +02:00
bind-9.18-CVE-2026-13204.patch Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) 2026-08-25 14:51:13 +02:00
bind-9.18-CVE-2026-13321-test.patch DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) 2026-08-25 14:51:41 +02:00
bind-9.18-CVE-2026-13321.patch DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) 2026-08-25 14:51:41 +02:00
bind-9.18-dig-idn-input-always-test.patch Fix expectations on idna system test 2025-10-03 16:18:14 +02:00
bind-9.18-dig-idn-input-always.patch Decode IDN names on input in all situations in utilities (rhbz#2324186) 2025-09-03 18:43:54 +02:00
bind-9.18-partial-additional-records.patch Offer up to 13 additional servers records 2025-09-02 12:01:28 +02:00
bind-9.18-pkcs11-provider.patch Update to 9.18.43 (rhbz#2415842) 2025-12-17 19:07:52 +01:00
bind-9.18-unittest-netmgr-unstable.patch Disable more test cases in netmgr_test (#2122010) 2022-09-14 15:59:18 +02:00
bind-9.20-nsupdate-tls-doc.patch Backport nsupdate TLS support 2024-12-09 21:08:34 +01:00
bind-9.20-nsupdate-tls-test.patch Include a test for nsupdate changes 2024-12-09 21:21:54 +01:00
bind-9.20-nsupdate-tls.patch Update to 9.18.43 (rhbz#2415842) 2025-12-17 19:07:52 +01:00
bind-chroot.tmpfiles.d Add forgotten _libdir/named into bind-chroot tmpfiles 2026-01-28 11:47:33 +01:00
bind.spec DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) 2026-08-25 14:51:41 +02:00
bind.tmpfiles.d Move named.local* and named.empty into /usr/share/named 2025-10-10 19:44:35 +02:00
bind97-exportlib.patch update to 9.9.3rc2 2013-05-13 12:50:46 +02:00
Changes.md Update Changes and README to match 9.16 release 2021-01-15 17:09:33 +01:00
ci.fmf adding ci.fmf with multiple plans support 2022-01-25 11:35:08 +00:00
codesign2019.txt Import version from branch v9_18 2022-08-03 20:37:06 +02:00
gating.yaml Adding fmf plan 2022-01-04 11:16:17 +01:00
generate-rndc-key.sh Correct shell warnings detected by coverity 2022-01-18 14:31:43 +01:00
isc-keyblock.asc Update to 9.18.16 (#2216462) 2023-06-22 00:34:42 +02:00
ldap2zone.c - updates due libtool 2.2.6 2008-11-24 12:59:15 +00:00
makefile-replace-libs.py Add helper for testing system daemons 2019-11-07 14:41:36 +01:00
named-chroot-setup.service Use new config named-chroot.files for chroot setup files (#1429656) 2018-07-13 14:11:20 +02:00
named-chroot.files Move named.local* and named.empty into /usr/share/named 2025-10-10 19:44:35 +02:00
named-chroot.service Enable automatic restart on crashes 2022-09-30 12:58:12 +02:00
named-setup-rndc.service Rework the chroot setup/destruction workflow 2013-12-17 17:09:44 +01:00
named.conf Reference to absolute config names from named.rfc1912.zones 2025-10-10 19:44:49 +02:00
named.conf.sample Replace master with primary in configuration 2022-01-25 15:07:27 +01:00
named.empty Remove config archive with zone files 2019-11-04 21:45:08 +01:00
named.localhost Remove config archive with zone files 2019-11-04 21:45:08 +01:00
named.logrotate logrotate: skip if empty and remove old variants 2025-09-05 18:58:15 +02:00
named.loopback Remove config archive with zone files 2019-11-04 21:45:08 +01:00
named.rfc1912.zones Reference to absolute config names from named.rfc1912.zones 2025-10-10 19:44:49 +02:00
named.root Update changed b.root-servers.net address in hints (#2253460) 2024-01-16 11:14:58 +01:00
named.root.key Add new root key 38696 into package files too 2024-12-12 21:25:14 +01:00
named.service Enable automatic restart on crashes 2022-09-30 12:58:12 +02:00
named.sysconfig Make comment how to use different config file 2017-07-14 17:02:15 +02:00
named.sysusers Add sysusers named user creation (rhbz#2105415) 2025-02-02 16:06:38 +01:00
README.md Remove permanently removed parts from README 2025-09-16 19:00:55 +02:00
setup-named-chroot.sh Import version from branch v9_18 2022-08-03 20:37:06 +02:00
setup-named-softhsm.sh Fix spec usage of softhsm helper 2019-02-22 16:39:54 +01:00
softhsm2.conf.in Enable unit tests with kyua tool (#1532694) 2018-01-09 18:19:43 +01:00
sources Update to 9.18.50 (rhbz#2489833) 2026-06-24 10:59:45 +02:00
trusted-key.key Add new root key 38696 into package files too 2024-12-12 21:25:14 +01:00

BIND 9

BIND (Berkeley Internet Name Domain) is a complete, highly portable implementation of the DNS (Domain Name System) protocol.

Internet Systems Consortium (https://www.isc.org), a 501(c)(3) public benefit corporation dedicated to providing software and services in support of the Internet infrastructure, developed BIND 9 and is responsible for its ongoing maintenance and improvement.

More details about upstream project can be found on their gitlab. This repository contains only upstream sources and packaging instructions for Fedora Project.

Any rebase requires to be built together with bind-dyndb-ldap to prevent conflict at installation of freeipa-server-dns. Stable bodhi updates are checked, but rawhide are not checked explicitly. Symbol of libraries in bind-libs changes with every minor version change of bind, therefore they break any package dependent on bind-libs.

Subpackages

The package contains several subpackages, some of them can be disabled on rebuild.

  • bind -- named daemon providing DNS server
  • bind-utils -- set of tools to analyse DNS responses or update entries (dig, host)
  • bind-doc -- documentation for current bind, BIND 9 Administrator Reference Manual.
  • bind-libs -- Shared libraries used by some others programs
  • bind-devel -- Development headers for libs. Can be disabled by --without DEVEL

Optional features

  • GSSTSIG -- Support for Kerberos authentication in BIND.
  • LMDB -- Support for dynamic database for managing runtime added zones. Provides faster removal of added zone with much less overhead. But requires lmdb linked to base libs.