]> git.99rst.org Git - openwrt-packages.git/commit
bind: bump to 9.20.29
authorNoah Meyerhans <redacted>
Fri, 18 Sep 2026 14:56:47 +0000 (10:56 -0400)
committerJosef Schlehofer <redacted>
Fri, 18 Sep 2026 15:46:40 +0000 (17:46 +0200)
commit799265743741fec9f44ad680957d6ce0c6902c2e
tree7e003d084ea30a2ea5a9737ec069fa87bac7864f
parent66c7c55e4ac3756c689b7cc147c3e5139e093503
bind: bump to 9.20.29

Includes several security fixes:

 - CVE-2026-19668 Prevent excessive CPU use validating crafted DNSSEC
   responses.

 - CVE-2026-19033 Require a TSIG on every message of incoming zone
   transfers.

 - CVE-2026-77119 Prevent a DNSSEC downgrade of secure delegations via
   unrelated NSEC3.

 - CVE-2026-19941 Prevent forged DNSSEC-validated NXDOMAIN responses.

 - CVE-2026-19666 DNS64 with break-dnssec could cause an assertion failure.

 - CVE-2026-19667 Reject negative cache records that do not fit in a
   dns_rdata_t.

 - CVE-2026-19662 Prevent resolver crash with cached DNSSEC proofs.

 - CVE-2026-75029 Discard repeated SOA, CNAME, and DNAME records when
   parsing DNS messages.

 - CVE-2026-77692 Fix an unauthenticated crash on HTTPS using SIG(0)

 - CVE-2026-81736 Cached HTTPS/SVCB aliases could exhaust resolver CPU.

 - CVE-2026-76163 Prevent TKEY queries from terminating named without global
   options.

 - CVE-2026-78301 Out-of-zone records in a zone database could be served as
   authoritative.

 - CVE-2026-80274 Crash on wildcard answers carrying both NSEC and NSEC3
   proofs.

 - CVE-2026-81563 Following HTTPS/SVCB aliases could leak resolver cache
   memory.

Complete upstream changelog is available at
https://ftp.isc.org/isc/bind9/9.20.29/doc/arm/html/changelog.html

Signed-off-by: Noah Meyerhans <redacted>
net/bind/Makefile
net/bind/patches/fix-usr-allow-rndc-addzone#1.patch
git clone https://git.99rst.org/PROJECT