BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

General Security Talk, Announcements and News
Post Reply
Starburst-David
Posts: 314
Joined: Wed Feb 11, 2026 8:31 pm

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Post by Starburst-David »

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).

A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature.


Full article at:
https://thehackernews.com/2026/09/bind- ... uding.html


Published Date: Sep 17, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-80274 CVE-2026-77119 CVE-2026-76163 CVE-2026-75029 CVE-2026-19668 CVE-2026-19666 CVE-2026-19033 CVE-2026-81736 CVE-2026-81563 CVE-2026-78301 CVE-2026-77692 CVE-2026-19941 CVE-2026-19667 CVE-2026-19662
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “General”