[ALSA-2026:54509] Important: bind9.16 security update
Type:
security
Severity:
important
Release date:
2026-08-13
Description:
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): * bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) * bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) * bind: bind9: Potential memory usage beyond configured limits (CVE-2026-11622) * bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721) * bind: bind9: Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204) * bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 bind9.16-libs-9.16.23-0.22.el8_10.12.aarch64.rpm 0c1e6e472939d2feb5a26c83d4875a8af613bf1febd7c5bc6ddfcac6caccfbed
aarch64 bind9.16-devel-9.16.23-0.22.el8_10.12.aarch64.rpm 19a640f64bee89b9cd7b3be82467ed568c0724a42842e302b3b83817507faff8
aarch64 bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.aarch64.rpm 363a34a0b8eee87eaaff5edc6100b4d3414cd50273229d2f4e26e3ebcb9b04ad
aarch64 bind9.16-9.16.23-0.22.el8_10.12.aarch64.rpm 7864de18137b6067e9e7968dc941fdb5ec7a0cb687b2449b357fbb5454a71f09
aarch64 bind9.16-utils-9.16.23-0.22.el8_10.12.aarch64.rpm 8030850cf05f125dec8a484153520e59eff02598b2446e8700043a192bbebc53
aarch64 bind9.16-chroot-9.16.23-0.22.el8_10.12.aarch64.rpm d04425198a4a9dbb756ec1bd7939364f6216bc664ccec296786eee9992f7f4ed
i686 bind9.16-devel-9.16.23-0.22.el8_10.12.i686.rpm 176ba9d36dbf70bad0943a392403e5c8951240209e601f6520e09ad7899bf9cc
i686 bind9.16-libs-9.16.23-0.22.el8_10.12.i686.rpm a0ab63808bcb4d2c204b9b0975895d3936dee0aa31ed8f9c09cd1d1fc7a29716
noarch python3-bind9.16-9.16.23-0.22.el8_10.12.noarch.rpm 34c8312199542cba1fd838cbd85c4bcc8f0787e016a687f5c9ca954eca60a0f9
noarch bind9.16-doc-9.16.23-0.22.el8_10.12.noarch.rpm c246017f07fba7bc48002121fa9f4927e6a3c6e5b36542ded90df883a5c01245
noarch bind9.16-license-9.16.23-0.22.el8_10.12.noarch.rpm d69eecb5caf85a0212a72f146a0881f5f8978865d0b9261f1f53435af6f3c2e0
ppc64le bind9.16-libs-9.16.23-0.22.el8_10.12.ppc64le.rpm 4b98dbcb70081788022ffd8c88f420dd25cb0728fceb23751867a1856f2a96e2
ppc64le bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.ppc64le.rpm 6072be2623b70d963bac1a8f015e0f3cf2f7b8c0199b085bc251822bcfb66ba9
ppc64le bind9.16-devel-9.16.23-0.22.el8_10.12.ppc64le.rpm 78dfee09af79096a81757adcc5d502399df83a3d3d4efe38f9f2a34e470cb119
ppc64le bind9.16-9.16.23-0.22.el8_10.12.ppc64le.rpm 8e0ad09a3bfe0e6212ad40030dba550d38c3ad583120fa226198c297d549d375
ppc64le bind9.16-chroot-9.16.23-0.22.el8_10.12.ppc64le.rpm a2c9fb9ae54f9ef30e69e39caaae27ed3ce2dc31cd0778d2779bf68b2356eea7
ppc64le bind9.16-utils-9.16.23-0.22.el8_10.12.ppc64le.rpm ab99ae4183290e7aad4928f572e4565e6934a2b377994dbfd31e016a7cb3e872
s390x bind9.16-utils-9.16.23-0.22.el8_10.12.s390x.rpm 17e44fec907aaa91c20294b37e8d164216090ed07524bc38800c0179e507542a
s390x bind9.16-chroot-9.16.23-0.22.el8_10.12.s390x.rpm 396946b1e3f164cc0041f594b0863d98700e417a01245cf80129e2234102f12a
s390x bind9.16-libs-9.16.23-0.22.el8_10.12.s390x.rpm 637560cf704c32902d6ca2c06ba288a827d0901fd0ab10d24240ecea0cd0828f
s390x bind9.16-9.16.23-0.22.el8_10.12.s390x.rpm 7b922e81289a170e45ab598c7d2f917cf8ea919d5f0c41e18e917f1cb1632b65
s390x bind9.16-devel-9.16.23-0.22.el8_10.12.s390x.rpm 8a4dc064b01126bda47280e136582c13b203f88c08d0cbeda9f48f0bad53cb61
s390x bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.s390x.rpm f9579656ccc5860a3bf49dd7401b17f89879cf37e2202d9aa8ea3a90bbc16286
x86_64 bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.x86_64.rpm 1bebb100db1155802c54d3a89bd5e57dccbabf6ed764929d0daff5b3f2a09c22
x86_64 bind9.16-utils-9.16.23-0.22.el8_10.12.x86_64.rpm 799e16e0f480232f06e748e48d4983d48e327d27777be51a8d1614f46c94a5d9
x86_64 bind9.16-9.16.23-0.22.el8_10.12.x86_64.rpm 8e5668bd9210eb43d73b466311b1a7b7974ff0f844d12fc660fffe112c651f24
x86_64 bind9.16-libs-9.16.23-0.22.el8_10.12.x86_64.rpm 9c38c92d6e7fe65098e673b2514b96ccef0706b4171247c55be66e07c4b044e6
x86_64 bind9.16-chroot-9.16.23-0.22.el8_10.12.x86_64.rpm d43123b6e509760f41cba951b6397a4ac051cfc73a00d69fd4ca497e1f0a2562
x86_64 bind9.16-devel-9.16.23-0.22.el8_10.12.x86_64.rpm fa1906b66c0f74b5738dd70013fd01c79d31c2d933afc32fca38232d5d757db2
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.