Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:1351-1 — bind (CVE-2026-1519 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for bind

This update for bind fixes the following issues:

Security issues:

  • CVE-2026-1519: maliciously crafted DNSSEC-validated zone can lead to denial of service (bsc#1260805).
  • CVE-2026-3104: memory leak in code preparing DNSSEC proofs of non-existence allows for DoS (bsc#1260567).
  • CVE-2026-3119: authenticated queries containing a TKEY record may cause named to terminate unexpectedly

(bsc#1260568).

  • CVE-2026-3591: stack use-after-return flaw in SIG(0) handling code allows for ACL bypass (bsc#1260569).
  • use-after-free error in dns_client_resolve() triggered by a DNAME response (bsc#1259202).

Upgrade to release 9.20.21

Security Fixes:

  • Fix unbounded NSEC3 iterations when validating referrals to

unsigned delegations.

(CVE-2026-1519)

[bsc#1260805]

  • Fix memory leaks in code preparing DNSSEC proofs of

non-existence.

(CVE-2026-3104)

[bsc#1260567]

  • Prevent a crash in code processing queries containing a TKEY

record.

(CVE-2026-3119)

[bsc#1260568]

  • Fix a stack use-after-return flaw in SIG(0) handling code.

(CVE-2026-3591)

[bsc#1260569]

  • Fix a use-after-free error in dns_client_resolve() triggered by

a DNAME response. This issue only affected the delv tool and it

has now been fixed.

[bsc#1259202]

Feature Changes:

  • Record query time for all dnstap responses.
  • Optimize TCP source port selection on Linux.

Bug Fixes:

  • Fix the handling of key statements defined inside views.
  • Fix an assertion failure triggered by non-minimal IXFRs.
  • Fix a crash when retrying a NOTIFY over TCP.
  • Fetch loop detection improvements.
  • Randomize nameserver selection.
  • Fix dnstap logging of forwarded queries.
  • A stale answer could have been served in case of multiple

upstream failures when following CNAME chains. This has been

fixed.

  • Fail DNSKEY validation when supported but invalid DS is found.
  • Importing an invalid SKR file might corrupt stack memory.
  • Return FORMERR for queries with the EDNS Client Subnet FAMILY

field set to 0.

  • Fix inbound IXFR performance regression.
  • Make catalog zone names and member zones' entry names

case-insensitive.

  • Fix implementation of BRID and HHIT record types.
  • Fix implementation of DSYNC record type.
  • Fix response policy and catalog zones to work with $INCLUDE

directive.

Affected software

SUSE-SU-2026:1351-1 is recorded against 1 package.

  • bind (fixed in 9.20.21-150700.3.18.1)

Timeline and source

Published on 15 April 2026 and last revised on 16 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-04-15
Updated 2026-08-20
Modified 2026-04-16
Fix URL N/A

Affected Packages

Software From version Fixed in
bind 9.20.21-150700.3.18.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:1351-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:1351-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.