🛡️ openSUSE-SU-2026:20091-1 — bind (CVE-2025-13878)
Description
Security update for bind
This update for bind fixes the following issues:
Upgrade to release 9.20.18:
- CVE-2025-13878: Fixed incorrect length checks for BRID and HHIT records (bsc#1256997)
Feature Changes:
- Add more information to the rndc recursing output about
fetches.
- Reduce the number of outgoing queries.
- Provide more information when memory allocation fails.
Bug Fixes:
- Make DNSSEC key rollovers more robust.
- Fix a catalog zone issue, where member zones could fail to
load.
- Allow glue in delegations with QTYPE=ANY.
- Fix slow speed when signing a large delegation zone with NSEC3
opt-out.
- Reconfiguring an NSEC3 opt-out zone to NSEC caused the zone to
be invalid.
- Fix a possible catalog zone issue during reconfiguration.
- Fix the charts in the statistics channel.
- Adding NSEC3 opt-out records could leave invalid records in
chain.
- Fix spurious timeouts while resolving names.
- Fix bug where zone switches from NSEC3 to NSEC after
retransfer.
- AMTRELAY type 0 presentation format handling was wrong.
- Fix parsing bug in remote-servers with key or TLS.
- Fix DoT reconfigure/reload bug in the resolver.
- Skip unsupported algorithms when looking for a signing key.
- Fix dnssec-keygen key collision checking for KEY RRtype keys.
- dnssec-verify now uses exit code 1 when failing due to illegal
options.
- Prevent assertion failures of dig when a server is specified
before the -b option.
- Skip buffer allocations if not logging.
Affected software
openSUSE-SU-2026:20091-1 is recorded against 1 package.
- bind (fixed in 9.20.18-160000.1.1)
Timeline and source
Published on 22 January 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| bind | — | 9.20.18-160000.1.1 |
References
Similar Threats
- Unknown ALPINE-CVE-2023-50387
- Unknown ALPINE-CVE-2023-50868
- Unknown ALPINE-CVE-2023-4408
- Unknown ALPINE-CVE-2023-5517
- Unknown ALPINE-CVE-2023-3341
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:20091-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20091-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.