Skip to content

[Deepin Integration]~[v25-Release] fix(cve): CVE-2026-76163 - Always create the TKEY context by deepin-ci-robot@deepin-community/bind9 by deepin-community-ci-bot[bot] #14011

Description

@deepin-bot

Package information | 软件包信息

包名 版本
bind9 1:9.20.23-1~deb13u1deepin12

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4573/testing/ ./

Changelog | 更新信息

bind9 (1:9.20.23-1~deb13u1deepin12) unstable; urgency=medium

[ deepin-ci-robot ]

[ lichenggang ]

  • fix(cve): complete the CVE-2026-77119 backport - require the NSEC3
    owner zone to enclose the DS name; the label-depth check alone let
    an NSEC3 from an unrelated sibling zone downgrade a secure
    delegation
  • fix(cve): CVE-2026-81563 - guard the rdataset release on the SVCB
    additional-data error paths with dns_rdataset_isassociated()
  • fix(cve): CVE-2026-19668 - restore the per-DS validation quota
    charging from upstream patch 3/4
  • test: register tests/dns/message_test in Makefile.am for CVE-2026-
    75029 and adapt the CVE-2026-19941 and CVE-2026-77692 system tests
    to the 9.20 test harness
  • fix(cve): CVE-2026-19668 - also restore upstream patch 2/4, making
    an exhausted validation quota terminal in the fetch callbacks and in
    validated(), so the fetch is no longer retried

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions