SB2026080735 - openEuler 24.03 LTS SP1 update for bind



SB2026080735 - openEuler 24.03 LTS SP1 update for bind

Published: August 7, 2026

Security Bulletin ID SB2026080735
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 86% Low 14%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2026-10723)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to forge authenticated NXDOMAIN responses.

The vulnerability exists due to improper validation of child-zone NSEC3 records in BIND 9 when processing DNSSEC records. A remote attacker can provide incorrect child-zone NSEC3 records to forge authenticated NXDOMAIN responses.

The issue can affect sibling zones.


2) Input validation error (CVE-ID: CVE-2026-10822)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in DNS record text rendering when processing a stored DNS record with a PRIVATEDNS algorithm identifier length longer than the actual identifier data. A remote attacker can supply a specially crafted DNS record to cause a denial of service.

User interaction is required for BIND to later render the stored record to text.


3) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-11331)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass RPZ rules.

The vulnerability exists due to improper error handling in RPZ processing when processing sufficiently long query names that trigger a NAMETOOLONG condition with wildcard CNAME policies. A remote attacker can send a crafted query name to bypass RPZ rules.

The issue only affects resolvers that use RPZ with wildcard CNAME policies.


4) Input validation error (CVE-ID: CVE-2026-11721)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to poison the DNS cache.

The vulnerability exists due to improper input validation in named when processing DNS responses containing an RRSIG with fewer labels than the containing zone and wildcard records. A remote attacker can operate an authoritative zone that returns a specially crafted response to poison the DNS cache.

The issue has effect only when the resolver under attack has synth-from-dnssec yes; enabled, which is the default.


5) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-12617)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of record ordering and response content in named resolver processing when processing responses to queries for CNAME or DNAME and A records. A remote attacker can send specially crafted DNS responses to cause a denial of service.

The issue is triggered when an authoritative server returns responses in a specific order, including delayed negative DNAME replies or a delayed self-referential CNAME reply.


6) Reachable assertion (CVE-ID: CVE-2026-13204)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an assertion failure in the DNSSEC validation logic when validating a provably insecure domain covered by both an NSEC and NSEC3 record at the parent with an RRSIG for only one of these types. A remote attacker can provide crafted DNS data to cause a denial of service.


7) Input validation error (CVE-ID: CVE-2026-13321)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to poison the DNS cache and cause authenticated denial-of-service responses.

The vulnerability exists due to improper input validation in DNSSEC NSEC record validation when processing validly signed NSEC records whose next domain name points outside the signer's zone. A remote attacker can craft malicious NSEC records to poison the DNS cache and cause authenticated denial-of-service responses.

Exploitation requires control of any DNSSEC-signed zone.


Remediation

Install update from vendor's website.