RHSA-2026:60383: Important: bind security update
Important: bind security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946) bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-chrootto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-develto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-export-develto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-export-libsto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-libsto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-libs-liteto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-licenseto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-lite-develto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-pkcs11to a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-pkcs11-develto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-pkcs11-libsto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-pkcs11-utilsto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-sdbto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-sdb-chrootto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
redhat/bind-utilsto a version that resolves this vulnerability.Fixed in 9.11.4-26.P2.el7_9.21 - Upgrade
Upgrade
bindto a version that resolves this vulnerability.Patch CVE-2026-3039
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize systems running BIND components, especially DNS servers using named and environments relying on BIND resolver libraries or DNSSEC validation. The listed issues include denial of service, memory exhaustion, cache poisoning, DNSSEC validation bypass, and unexpected process exit.
What attack conditions are identified for the affected issues?
The advisory identifies specially crafted DNS messages as the trigger for one denial-of-service issue and GSS-API TKEY negotiation as the context for a memory-exhaustion issue. It also identifies DNSSEC-related record handling and cache-processing conditions for several other vulnerabilities.
Which Red Hat packages are covered by this update?
The update covers bind, bind-chroot, bind-debuginfo, bind-devel, bind-export-devel, bind-export-libs, bind-libs, and bind-libs-lite.