AI Weekly Malaysia

Back to items Summaries

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

ID
25596
Status
summarized
Published
17 Sep 2026, 4:00 PM
Fetched
17 Sep 2026, 11:47 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
17 Sep 2026, 11:51 PM
Tags
Audience
developersdatabase_learners

What happened

ISC released BIND 9.20.29 and 9.21.26 to fix 14 security flaws, including CVE-2026-77692, which lets an unauthenticated sender crash any BIND server answering DNS-over-HTTPS with a single request carrying an invalid SIG(0) signature. There are no workarounds. The EOL 9.18 branch (including Debian 12's shipped 9.18.49) remains vulnerable with no fix planned.

Why it matters

If you run your own BIND resolver—especially on Debian 12, which ships 9.18.49—you are exposed to unpatched crash bugs with no workaround and must upgrade to 9.20.29 immediately. If you use managed DNS (Cloudflare, Route53, etc.), this likely doesn't affect you, but check whether any internal infrastructure runs BIND.

Discussion angle

How many of us actually run self-managed BIND vs. managed DNS, and does the Debian 12 shipping-an-EOL-version situation change how we think about distro-packaged infrastructure software?

Top