Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18786

Опубликовано: 12 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18786: bind security update (IMPORTANT)

[9.16.23-40.0.1.el9_8.1]

  • Fix warning when changing device file permissions [Orabug: 36518580]

[32:9.16.23-40.1]

  • Prevent Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519)

[32:9.16.23-40]

  • Add forgotten _libdir/named into bind-chroot tmpfiles (RHEL-135629)

[32:9.16.23-39]

  • Backport fix for nameserver line processing. (RHEL-79714)

[32:9.16.23-38]

  • Add sysusers named user creation (RHEL-132053)

[32:9.16.23-37]

  • Create /var/named directories for bind-chroot (RHEL-132053)

[32:9.16.23-36]

  • Copy named.* files from /var/named into /usr/share/named

[32:9.16.23-35]

  • Prevent cache poisoning due to weak PRNG (CVE-2025-40780)
  • Replace downstream fixes with upstream changes
  • Address various spoofing attacks (CVE-2025-40778)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

bind

9.16.23-40.0.1.el9_8.1

bind-chroot

9.16.23-40.0.1.el9_8.1

bind-devel

9.16.23-40.0.1.el9_8.1

bind-dnssec-doc

9.16.23-40.0.1.el9_8.1

bind-dnssec-utils

9.16.23-40.0.1.el9_8.1

bind-doc

9.16.23-40.0.1.el9_8.1

bind-libs

9.16.23-40.0.1.el9_8.1

bind-license

9.16.23-40.0.1.el9_8.1

bind-utils

9.16.23-40.0.1.el9_8.1

python3-bind

9.16.23-40.0.1.el9_8.1

Oracle Linux x86_64

bind

9.16.23-40.0.1.el9_8.1

bind-chroot

9.16.23-40.0.1.el9_8.1

bind-devel

9.16.23-40.0.1.el9_8.1

bind-dnssec-doc

9.16.23-40.0.1.el9_8.1

bind-dnssec-utils

9.16.23-40.0.1.el9_8.1

bind-doc

9.16.23-40.0.1.el9_8.1

bind-libs

9.16.23-40.0.1.el9_8.1

bind-license

9.16.23-40.0.1.el9_8.1

bind-utils

9.16.23-40.0.1.el9_8.1

python3-bind

9.16.23-40.0.1.el9_8.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
9 месяцев назад

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
redhat
9 месяцев назад

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
nvd
9 месяцев назад

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVSS3: 7.5
msrc
8 месяцев назад

Resource exhaustion via malformed DNSKEY handling

CVSS3: 7.5
debian
9 месяцев назад

Querying for records within a specially crafted zone containing certai ...