BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
- ID
- 25596
- Status
- summarized
- Published
- 17 Sep 2026, 4:00 PM
- Fetched
- 17 Sep 2026, 11:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 17 Sep 2026, 11:51 PM
- Tags
- Audience
- developersdatabase_learners
What happened
ISC released BIND 9.20.29 and 9.21.26 to fix 14 security flaws, including CVE-2026-77692, which lets an unauthenticated sender crash any BIND server answering DNS-over-HTTPS with a single request carrying an invalid SIG(0) signature. There are no workarounds. The EOL 9.18 branch (including Debian 12's shipped 9.18.49) remains vulnerable with no fix planned.
Why it matters
If you run your own BIND resolver—especially on Debian 12, which ships 9.18.49—you are exposed to unpatched crash bugs with no workaround and must upgrade to 9.20.29 immediately. If you use managed DNS (Cloudflare, Route53, etc.), this likely doesn't affect you, but check whether any internal infrastructure runs BIND.
Discussion angle
How many of us actually run self-managed BIND vs. managed DNS, and does the Debian 12 shipping-an-EOL-version situation change how we think about distro-packaged infrastructure software?