-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 20 May 2026 12:21:44 +0200 Source: bind9 Binary: bind9 bind9-dbgsym bind9-dev bind9-dnsutils bind9-dnsutils-dbgsym bind9-host bind9-host-dbgsym bind9-libs bind9-libs-dbgsym bind9-utils bind9-utils-dbgsym Architecture: i386 Version: 1:9.20.23-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Ondřej Surý Description: bind9 - Internet Domain Name Server bind9-dev - Static Libraries and Headers used by BIND 9 bind9-dnsutils - Clients provided with BIND 9 bind9-host - DNS Lookup Utility bind9-libs - Shared Libraries used by BIND 9 bind9-utils - Utilities for BIND 9 Changes: bind9 (1:9.20.23-1~deb13u1) trixie-security; urgency=high . * New upstream version 9.20.23 + [CVE-2026-3592]: Limit resolver server list size. + [CVE-2026-3039]: Fix GSS-API resource leak. + [CVE-2026-5946]: Disable recursion, UPDATE, and NOTIFY for non-IN views. + [CVE-2026-5950]: Avoid unbounded recursion loop. + [CVE-2026-5947]: Fix crash in resolver when SIG(0)-signed responses are received under load. + [CVE-2026-3593]: Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. Checksums-Sha1: 975b46cbef2ae855a291fee6f163b43fa7f3c89d 610416 bind9-dbgsym_9.20.23-1~deb13u1_i386.deb b5101d549b1078bdb38f3d77cf870a9099c5c6b0 294764 bind9-dev_9.20.23-1~deb13u1_i386.deb 5b5ccec263143f034bf68bbe64e981acd21695f8 392084 bind9-dnsutils-dbgsym_9.20.23-1~deb13u1_i386.deb beac31ac8ed4aa5a9b917d251b9f7c7691920424 170260 bind9-dnsutils_9.20.23-1~deb13u1_i386.deb edbed4f6c3fe6ec4dbd6bcd6d560252abf9a7897 93956 bind9-host-dbgsym_9.20.23-1~deb13u1_i386.deb 5da02986481c0c564a82ae2457c9ceaca18f6028 57728 bind9-host_9.20.23-1~deb13u1_i386.deb 34f6a3bc021950fa7d248f14c6a09479760b52e4 3531584 bind9-libs-dbgsym_9.20.23-1~deb13u1_i386.deb 052313ffeee3379e61a3228a9343627b1a55aeaa 1323392 bind9-libs_9.20.23-1~deb13u1_i386.deb 36255ef732a3c0f00419d285d320788fc29d627b 448940 bind9-utils-dbgsym_9.20.23-1~deb13u1_i386.deb e1f4396f30ad81a92fc51f08ea56d7e8ef2a0f66 185872 bind9-utils_9.20.23-1~deb13u1_i386.deb 1a351cdea1f3c96359fb34a871a80600815c8f86 10348 bind9_9.20.23-1~deb13u1_i386-buildd.buildinfo 7e51117c28bea1203d9a029ffed06664603b8ec8 269628 bind9_9.20.23-1~deb13u1_i386.deb Checksums-Sha256: 9d3b8755f61711dc9c4c89a2611fd0b4f67c88bb6bf5e7f837346e31e243c21d 610416 bind9-dbgsym_9.20.23-1~deb13u1_i386.deb 5eea94ea122a30aa51b3e4421eeafc365f1c980e7c5feafc8174f6afd6ad6006 294764 bind9-dev_9.20.23-1~deb13u1_i386.deb d343d718e6060412387298148e8232b1a1b0dd0d324630fb6603f3ee0e34451a 392084 bind9-dnsutils-dbgsym_9.20.23-1~deb13u1_i386.deb 2223d5953d802d9456823e5d63147c6b554457b540b1ba0f490ed1e97ec3d91e 170260 bind9-dnsutils_9.20.23-1~deb13u1_i386.deb 396cb868f125ebf92722745631cf81d17491b2408ad0b532d9ba9475d492463a 93956 bind9-host-dbgsym_9.20.23-1~deb13u1_i386.deb 9d274cc879e1df3731b849a9ce3bd428f607201dd396bc739dae11e33a1ddb2b 57728 bind9-host_9.20.23-1~deb13u1_i386.deb 88e847b07479f25040ed84938d767366fcfeef5709cd4ea8ba3a3f07ee43f4d8 3531584 bind9-libs-dbgsym_9.20.23-1~deb13u1_i386.deb 443b5999f309f892977961d1f0873a1a40bbf517243e7af7484491f24e131b3f 1323392 bind9-libs_9.20.23-1~deb13u1_i386.deb f5dd53bb19240a567e2a4ee368e32064553e7d104ea7e24f637990cd4d3aeaaa 448940 bind9-utils-dbgsym_9.20.23-1~deb13u1_i386.deb ca47dafe9091faac8780f8d222c4f482fa44e30f7f1e7ed9518cc864c20a64f1 185872 bind9-utils_9.20.23-1~deb13u1_i386.deb 0db7fef51a031ffc833c1d95972ed93950310fdb93063741b26bb71e686e322d 10348 bind9_9.20.23-1~deb13u1_i386-buildd.buildinfo 4992bfe36c189c77c1b5e30433da1b05590c69af55c6e8b317853c109662be92 269628 bind9_9.20.23-1~deb13u1_i386.deb Files: a137eba2b269d39fc864586d5a1681c1 610416 debug optional bind9-dbgsym_9.20.23-1~deb13u1_i386.deb af153627450ab55f7e790ed6eec61421 294764 devel optional bind9-dev_9.20.23-1~deb13u1_i386.deb 18d29c4e6da343b010500bffb2731fa1 392084 debug optional bind9-dnsutils-dbgsym_9.20.23-1~deb13u1_i386.deb 74f6dab0216e08e01d780233680a184d 170260 net standard bind9-dnsutils_9.20.23-1~deb13u1_i386.deb 9ef396b3ddd0dfe589a2831a03beceff 93956 debug optional bind9-host-dbgsym_9.20.23-1~deb13u1_i386.deb 313dd560d645fcfdda7c691fef1b2d69 57728 net standard bind9-host_9.20.23-1~deb13u1_i386.deb 48efcf8585a156a6d878acfa5d2a3a57 3531584 debug optional bind9-libs-dbgsym_9.20.23-1~deb13u1_i386.deb 2714e2fe3dfde657e86ea7d75c5bd28f 1323392 libs standard bind9-libs_9.20.23-1~deb13u1_i386.deb 224be33d21822e9814371ffc3c440f58 448940 debug optional bind9-utils-dbgsym_9.20.23-1~deb13u1_i386.deb 28339fa3154446a575548a737d454a4b 185872 net optional bind9-utils_9.20.23-1~deb13u1_i386.deb 5ba17468edfcde927cddee864ea296ce 10348 net optional bind9_9.20.23-1~deb13u1_i386-buildd.buildinfo 0293bd6871d84769a231352009884e03 269628 net optional bind9_9.20.23-1~deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmoNlOYACgkQf2INRiCd aWIjew/9FTIeB+Ry/uWi7rrxw3wzrSeVdinyrFCR3688/iabI3fBReQpe5G9ytuI ziSIA8ZBlxOLEOQuPmS7e9POUB4l9XwIkmGVL6X/maxKDGK14/ETgjduwUti1qpZ Ult+aW0dkTUMlqw4agUeS9VDR6/xLuHQrgOWKJcEtd5D7r5yvBFQMlGJ8biUiQ/5 fa45/T3WEKz03rtzQQQmDRiNnFsMiAzn7vDrsiuaeaeoGJaM4mc3bm/CGfIGoKxm ev+pZ/ShTYt1X+zO+ZBwZb4Y/jC0kuHM2eBs5I7L1kSUgSqY0UP0TEmFMZi7Ysa7 HStxGc2RePa4lyutrP4F+jF/Nr3nmPf56BOw2CXKrCu/JLP2OhyusOQeWyCfiMlt Y6r/IOzXLmrDiBiVCXS8l13cutT6lfwIOtwGyx3gzCFmwaCaKU4RnJOy5pstvwJm iEFWixeCJmSvg9A5mIWRowCa3SVeKtqHFD+u0+PYvr8nCQFvpuWGh6QKOErfHdt9 SOyILmS7Nq2PvM9D4hy3XKLle3CDX0EC9fesgavKfBsPafczDy5RmpxuVtws5KBp nyM1PRNdGiCiTkkwmPd/+4Fs6eN0KvJFoeftwSumjvzs9ZXZOsu8fCVopFiSCjqs n/owVrXgW9J+27z8QbB59/e2HC70Q/J+vW8S7oeF+R5zPa5EL1M= =5X5s -----END PGP SIGNATURE-----