You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Deepin Integration]~[v25-Release] fix(cve): CVE-2026-76163 - Always create the TKEY context by deepin-ci-robot@deepin-community/bind9 by deepin-community-ci-bot[bot] #14011
fix(cve): CVE-2026-77692 (high) - Fix an unauthenticated crash on
HTTPS using SIG(0) Upstream: https://github.com/isc-
projects/bind9/commit/d1c25323509173e4d65785e1d1781de77bf461a6.patch
fix(cve): CVE-2026-19666 (high) - [PATCH 1/2] Clear the noqname
alias on the DNS64 filter64 path Upstream: https://github.com/isc-
projects/bind9/commit/9ddfd2e4da7374ab2f6eaa67cd48d99116a8f60e,https
://github.com/isc-
projects/bind9/commit/bc4a9ce4d3940f1c5f02f885253e7fbe201de7c4
fix(cve): CVE-2026-19941 (medium) - [PATCH] Require NSEC wildcard
proofs from the same zone Upstream: https://github.com/isc-
projects/bind9/commit/ac43c3163839ef171a8ca0376291f97bc8ea9487
fix(cve): CVE-2026-77119 (medium) - [CVE-2026-77119] sec: usr:
Prevent a DNSSEC downgrade of secure delegations via unrelated NSEC3
Upstream: https://github.com/isc-
projects/bind9/commit/f76b3440b4133337a1794abefe7655becd483118
fix(cve): CVE-2026-19668 (medium) - [CVE-2026-19668] sec: usr:
Prevent excessive CPU use validating crafted DNSSEC responses
Upstream: https://github.com/isc-
projects/bind9/commit/8d660756e89e896b6f54ede08a96578c9f011c2a
fix(cve): CVE-2026-19033 (medium) - Remove support for sparse TSIG
Upstream: https://github.com/isc-
projects/bind9/commit/fa351e24e2f97777a3087a9f91998e22cd336deb.patch
[ lichenggang ]
fix(cve): complete the CVE-2026-77119 backport - require the NSEC3
owner zone to enclose the DS name; the label-depth check alone let
an NSEC3 from an unrelated sibling zone downgrade a secure
delegation
fix(cve): CVE-2026-81563 - guard the rdataset release on the SVCB
additional-data error paths with dns_rdataset_isassociated()
fix(cve): CVE-2026-19668 - restore the per-DS validation quota
charging from upstream patch 3/4
test: register tests/dns/message_test in Makefile.am for CVE-2026-
75029 and adapt the CVE-2026-19941 and CVE-2026-77692 system tests
to the 9.20 test harness
fix(cve): CVE-2026-19668 - also restore upstream patch 2/4, making
an exhausted validation quota terminal in the fetch callbacks and in
validated(), so the fetch is no longer retried
Package information | 软件包信息
Package repository address | 软件包仓库地址
Changelog | 更新信息
bind9 (1:9.20.23-1~deb13u1deepin12) unstable; urgency=medium
[ deepin-ci-robot ]
Upstream: isc-projects/bind9@4a48f9b73f
HTTPS using SIG(0) Upstream: https://github.com/isc-
projects/bind9/commit/d1c25323509173e4d65785e1d1781de77bf461a6.patch
alias on the DNS64 filter64 path Upstream: https://github.com/isc-
projects/bind9/commit/9ddfd2e4da7374ab2f6eaa67cd48d99116a8f60e,https
://github.com/isc-
projects/bind9/commit/bc4a9ce4d3940f1c5f02f885253e7fbe201de7c4
additional-data lookups fail Upstream:
CVEProject/cvelistV5@3da381e3163f31ce28407
ba16d4a5b2277cd5f26
proofs from the same zone Upstream: https://github.com/isc-
projects/bind9/commit/ac43c3163839ef171a8ca0376291f97bc8ea9487
Prevent a DNSSEC downgrade of secure delegations via unrelated NSEC3
Upstream: https://github.com/isc-
projects/bind9/commit/f76b3440b4133337a1794abefe7655becd483118
Upstream: https://github.com/isc-
projects/bind9/commit/905f6cc0a3f5347eb849b33fdbe4898e2445e47d.patch
Prevent excessive CPU use validating crafted DNSSEC responses
Upstream: https://github.com/isc-
projects/bind9/commit/8d660756e89e896b6f54ede08a96578c9f011c2a
Upstream: https://github.com/isc-
projects/bind9/commit/fa351e24e2f97777a3087a9f91998e22cd336deb.patch
[ lichenggang ]
owner zone to enclose the DS name; the label-depth check alone let
an NSEC3 from an unrelated sibling zone downgrade a secure
delegation
additional-data error paths with dns_rdataset_isassociated()
charging from upstream patch 3/4
75029 and adapt the CVE-2026-19941 and CVE-2026-77692 system tests
to the 9.20 test harness
an exhausted validation quota terminal in the fetch callbacks and in
validated(), so the fetch is no longer retried