Page 1 of 1

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Posted: Fri Sep 18, 2026 5:12 am
by Starburst-David
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).

A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature.


Full article at:
https://thehackernews.com/2026/09/bind- ... uding.html


Published Date: Sep 17, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-80274 CVE-2026-77119 CVE-2026-76163 CVE-2026-75029 CVE-2026-19668 CVE-2026-19666 CVE-2026-19033 CVE-2026-81736 CVE-2026-81563 CVE-2026-78301 CVE-2026-77692 CVE-2026-19941 CVE-2026-19667 CVE-2026-19662