RHSA-2026:55442: Important: bind9.18 security update
BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.Security Fix(es): bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bind9.18to a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-chrootto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-debugsourceto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-libsto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-utilsto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18to a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-chrootto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-debugsourceto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-libsto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-utilsto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
redhat/bind9.18-develto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-docto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8 - Upgrade
Upgrade
redhat/bind9.18-develto a version that resolves this vulnerability.Fixed in 9.18.29-14.el9_8.8.aa - Upgrade
Upgrade
bind9to a version that resolves this vulnerability.Fixed in bind9.18 - Compensating control
Given this is a bind9.18 security update addressing multiple bind9 security issues (e.g., CVE-2026-11721, CVE-2026-13321, CVE-2026-10723, CVE-2026-11622, CVE-2026-13204, CVE-2026-11331), ensure the DNS server (named) is protected during patching by temporarily restricting/monitoring DNS query traffic to the server and validating service health after the update.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:55442?
The severity of RHSA-2026:55442 is classified as important.
How do I fix RHSA-2026:55442?
To fix RHSA-2026:55442, you should update the BIND packages to the latest version provided by Red Hat.
What systems are affected by RHSA-2026:55442?
RHSA-2026:55442 affects systems using the BIND 9.18 implementation on Red Hat.
What vulnerabilities are addressed in RHSA-2026:55442?
RHSA-2026:55442 addresses multiple vulnerabilities related to the BIND DNS server.
What components are included in the BIND 9.18 update for RHSA-2026:55442?
The BIND 9.18 update for RHSA-2026:55442 includes various components such as the DNS server, resolver library, and DNSSEC utilities.