Skip to main content

Security update for bind

0
High
Published: 10/09/2026 (10/09/2026, 15:54:44 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This security update for the BIND DNS software addresses multiple vulnerabilities, including unauthenticated application of IXFR deltas before TSIG verification, use-after-free crashes in recursive resolvers, remote assertion failures, and denial of service via cached AliasMode trees. The update fixes a range of issues that could lead to crashes, data leakage, or denial of service conditions. No CVSS score is provided, but the severity is assessed as high due to the nature of the vulnerabilities and their potential impact on DNS resolution.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/10/2026, 21:41:12 UTC

Technical Analysis

The update for BIND fixes several vulnerabilities: CVE-2026-19033 involves unauthenticated IXFR deltas being applied before TSIG verification, potentially allowing unauthorized zone modifications. CVE-2026-19662 and CVE-2026-19666 are use-after-free vulnerabilities causing crashes in the recursive resolver. CVE-2026-19667 is a remote assertion failure triggered by 16-bit length truncation. CVE-2026-19941 allows acceptance of out-of-zone NSEC records as wildcard-nonexistence proofs. CVE-2026-75029 involves message parser retaining identical singleton RDATA, enabling amplification. CVE-2026-78301 allows out-of-zone database nodes to become authoritative zone cuts. CVE-2026-80274 causes aborts while caching mismatched NOQNAME proofs. CVE-2026-81563 leaks qpcache references via SVCB AliasMode additional-data errors. CVE-2026-81736 enables remote CPU denial of service through cached SVCB/HTTPS AliasMode trees. These collectively impact DNS integrity, stability, and availability.

Potential Impact

The vulnerabilities can lead to unauthorized changes to DNS zones, crashes of recursive resolvers, denial of service conditions, and potential amplification attacks. These issues affect DNS resolution reliability and security, potentially disrupting network services relying on BIND. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

A security update for BIND has been released that addresses all listed vulnerabilities. Users should apply the update promptly to remediate these issues. Patch status is not explicitly confirmed in the provided data; therefore, check the SUSE Product Security Team advisory for the official patch and remediation details.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:4608-1
Cve Count
10
Additional Cves
["CVE-2026-19662","CVE-2026-19666","CVE-2026-19667","CVE-2026-19941","CVE-2026-75029","CVE-2026-78301","CVE-2026-80274","CVE-2026-81563","CVE-2026-81736"]
State
PUBLISHED

Threat ID: 6acaadb82cdf04f65651522d

Added to database: 10/10/2026, 21:27:20 UTC

Last enriched: 10/10/2026, 21:41:12 UTC

Last updated: 10/10/2026, 22:08:08 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses