RHSA-2026:54509: Important: bind9.16 security update
Important: bind9.16 security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-licenseto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/python3-bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-docto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12 - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.22.el8_10.12.aa - Upgrade
Upgrade
bind9 (named/bind9.16)to a version that resolves this vulnerability.Fixed in bind9.16 - Compensating control
Until the bind9.16 security update is applied, mitigate BIND DNS risks by restricting DNS query access to trusted networks/clients (e.g., via firewall/ACL) to reduce exposure to cache-poisoning and DNSSEC-validation bypass attempts.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54509?
The severity of RHSA-2026:54509 is rated as high with a score of 7.
How do I fix RHSA-2026:54509?
To fix RHSA-2026:54509, apply the latest security update for BIND 9.16 provided by Red Hat.
What is affected by RHSA-2026:54509?
RHSA-2026:54509 affects the BIND 9.16 implementation in various Red Hat packages including bind9.16 and its associated libraries.
What vulnerabilities are addressed in RHSA-2026:54509?
RHSA-2026:54509 addresses security flaws in BIND that could potentially lead to denial-of-service attacks or data leaks.
What is the importance of applying RHSA-2026:54509 promptly?
Applying RHSA-2026:54509 promptly is crucial to maintain the security and integrity of DNS operations in your environment.