]>
git.99rst.org Git - openwrt-packages.git/commit
bind: bump to 9.20.29
Includes several security fixes:
- CVE-2026-19668 Prevent excessive CPU use validating crafted DNSSEC
responses.
- CVE-2026-19033 Require a TSIG on every message of incoming zone
transfers.
- CVE-2026-77119 Prevent a DNSSEC downgrade of secure delegations via
unrelated NSEC3.
- CVE-2026-19941 Prevent forged DNSSEC-validated NXDOMAIN responses.
- CVE-2026-19666 DNS64 with break-dnssec could cause an assertion failure.
- CVE-2026-19667 Reject negative cache records that do not fit in a
dns_rdata_t.
- CVE-2026-19662 Prevent resolver crash with cached DNSSEC proofs.
- CVE-2026-75029 Discard repeated SOA, CNAME, and DNAME records when
parsing DNS messages.
- CVE-2026-77692 Fix an unauthenticated crash on HTTPS using SIG(0)
- CVE-2026-81736 Cached HTTPS/SVCB aliases could exhaust resolver CPU.
- CVE-2026-76163 Prevent TKEY queries from terminating named without global
options.
- CVE-2026-78301 Out-of-zone records in a zone database could be served as
authoritative.
- CVE-2026-80274 Crash on wildcard answers carrying both NSEC and NSEC3
proofs.
- CVE-2026-81563 Following HTTPS/SVCB aliases could leak resolver cache
memory.
Complete upstream changelog is available at
https://ftp.isc.org/isc/bind9/9.20.29/doc/arm/html/changelog.html
Signed-off-by: Noah Meyerhans <redacted>