• imports/c10s/bind-9.18.33-19.el10 0d395adab1

    Ghost released this 2026-06-24 13:03:14 +00:00 | -1124 commits to c8 since this release

    Recursion, dynamic updates (UPDATE), and zone change notifications
    (NOTIFY) are now disabled for views with a class other than IN
    (such as CHAOS or HESIOD); authoritative service for non-IN zones
    (e.g. version.bind in class CHAOS) continues to work as before.
    Servers configured with recursion yes in a non-IN view will log a
    warning at startup, and named-checkconf flags the same condition.
    UPDATE and NOTIFY messages that specify the meta-classes ANY or NONE
    in the question section are now rejected with FORMERR.

    This addresses a set of closely related security issues collectively
    identified as CVE-2026-5946. ISC would like to thank Mcsky23 for
    bringing these issues to our attention.

    Resolves-Vulnerability: CVE-2026-5946
    Resolves: RHEL-177671

    Downloads