RHSA-2026:55441: Important: bind security update
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946) bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-dnssec-docto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-libsto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-licenseto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/python3-bindto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-libsto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
redhat/bind-develto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-docto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4 - Upgrade
Upgrade
redhat/bind-develto a version that resolves this vulnerability.Fixed in 9.16.23-31.el9_6.4.aa - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-3039 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-11331 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-5946 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-11721 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-13321 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-10723 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-11622 - Upgrade
Upgrade
bind9 (BIND/named)to a version that resolves this vulnerability.Patch CVE-2026-13204 - Compensating control
If you cannot immediately apply the BIND security update, reduce exposure by limiting network access to the BIND (named) service (e.g., restrict inbound DNS traffic and admin/control-plane access to trusted sources only).