Security update for bind
Description
This security update for the BIND DNS software addresses multiple vulnerabilities, including unauthenticated application of IXFR deltas before TSIG verification, use-after-free crashes in recursive resolvers, remote assertion failures, and denial of service via cached AliasMode trees. The update fixes a range of issues that could lead to crashes, data leakage, or denial of service conditions. No CVSS score is provided, but the severity is assessed as high due to the nature of the vulnerabilities and their potential impact on DNS resolution.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The update for BIND fixes several vulnerabilities: CVE-2026-19033 involves unauthenticated IXFR deltas being applied before TSIG verification, potentially allowing unauthorized zone modifications. CVE-2026-19662 and CVE-2026-19666 are use-after-free vulnerabilities causing crashes in the recursive resolver. CVE-2026-19667 is a remote assertion failure triggered by 16-bit length truncation. CVE-2026-19941 allows acceptance of out-of-zone NSEC records as wildcard-nonexistence proofs. CVE-2026-75029 involves message parser retaining identical singleton RDATA, enabling amplification. CVE-2026-78301 allows out-of-zone database nodes to become authoritative zone cuts. CVE-2026-80274 causes aborts while caching mismatched NOQNAME proofs. CVE-2026-81563 leaks qpcache references via SVCB AliasMode additional-data errors. CVE-2026-81736 enables remote CPU denial of service through cached SVCB/HTTPS AliasMode trees. These collectively impact DNS integrity, stability, and availability.
Potential Impact
The vulnerabilities can lead to unauthorized changes to DNS zones, crashes of recursive resolvers, denial of service conditions, and potential amplification attacks. These issues affect DNS resolution reliability and security, potentially disrupting network services relying on BIND. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A security update for BIND has been released that addresses all listed vulnerabilities. Users should apply the update promptly to remediate these issues. Patch status is not explicitly confirmed in the provided data; therefore, check the SUSE Product Security Team advisory for the official patch and remediation details.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:4608-1
- Cve Count
- 10
- Additional Cves
- ["CVE-2026-19662","CVE-2026-19666","CVE-2026-19667","CVE-2026-19941","CVE-2026-75029","CVE-2026-78301","CVE-2026-80274","CVE-2026-81563","CVE-2026-81736"]
- State
- PUBLISHED
Threat ID: 6acaadb82cdf04f65651522d
Added to database: 10/10/2026, 21:27:20 UTC
Last enriched: 10/10/2026, 21:41:12 UTC
Last updated: 10/10/2026, 22:08:08 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.