• imports/c10s/bind-9.18.33-18.el10 d598399af2

    Ghost released this 2026-04-17 11:01:19 +00:00 | -1122 commits to c8 since this release

    DNSSEC-signed zones may contain high iteration-count NSEC3 records,
    which prove that certain delegations are insecure. Previously, a
    validating resolver encountering such a delegation processed these
    iterations up to the number given, which could be a maximum of 65,535.
    This has been addressed by introducing a processing limit, set at 150.
    Now, if such an NSEC3 record is encountered, the delegation will be
    treated as insecure.

    ISC would like to thank Samy Medjahed/Ap4sh for bringing this
    vulnerability to our attention.

    Closes isc-projects/bind9#5708

    Resolves-Vulnerability: CVE-2026-1519

    Downloads