Skip to content

bind: bump to 9.20.29 - #30558

Merged
BKPepe merged 1 commit into
openwrt:masterfrom
nmeyerhans:update-bind9
Sep 18, 2026
Merged

BKPepe merged 1 commit into
openwrt:masterfrom
nmeyerhans:update-bind9

Conversation

@nmeyerhans

Copy link
Copy Markdown
Contributor

📦 Package Details

Maintainer: @nmeyerhans

Description:

New upstream stable release 9.20.29

Includes several security fixes:

  • CVE-2026-19668 Prevent excessive CPU use validating crafted DNSSEC responses.

  • CVE-2026-19033 Require a TSIG on every message of incoming zone transfers.

  • CVE-2026-77119 Prevent a DNSSEC downgrade of secure delegations via unrelated NSEC3.

  • CVE-2026-19941 Prevent forged DNSSEC-validated NXDOMAIN responses.

  • CVE-2026-19666 DNS64 with break-dnssec could cause an assertion failure.

  • CVE-2026-19667 Reject negative cache records that do not fit in a dns_rdata_t.

  • CVE-2026-19662 Prevent resolver crash with cached DNSSEC proofs.

  • CVE-2026-75029 Discard repeated SOA, CNAME, and DNAME records when parsing DNS messages.

  • CVE-2026-77692 Fix an unauthenticated crash on HTTPS using SIG(0)

  • CVE-2026-81736 Cached HTTPS/SVCB aliases could exhaust resolver CPU.

  • CVE-2026-76163 Prevent TKEY queries from terminating named without global options.

  • CVE-2026-78301 Out-of-zone records in a zone database could be served as authoritative.

  • CVE-2026-80274 Crash on wildcard answers carrying both NSEC and NSEC3 proofs.

  • CVE-2026-81563 Following HTTPS/SVCB aliases could leak resolver cache memory.

Complete upstream changelog is available at
https://ftp.isc.org/isc/bind9/9.20.29/doc/arm/html/changelog.html


🧪 Run Testing Details

  • OpenWrt Version: pending
  • OpenWrt Target/Subtarget: pending
  • OpenWrt Device: WRT1900ACS

✅ Formalities

  • I have reviewed the CONTRIBUTING.md file for detailed contributing guidelines.

If your PR contains a patch:

  • It can be applied using git am
  • It has been refreshed to avoid offsets, fuzzes, etc., using
    make package/<your-package>/refresh V=s
  • It is structured in a way that it is potentially upstreamable
    (e.g., subject line, commit description, etc.)
    We must try to upstream patches to reduce maintenance burden.

Includes several security fixes:

 - CVE-2026-19668 Prevent excessive CPU use validating crafted DNSSEC
   responses.

 - CVE-2026-19033 Require a TSIG on every message of incoming zone
   transfers.

 - CVE-2026-77119 Prevent a DNSSEC downgrade of secure delegations via
   unrelated NSEC3.

 - CVE-2026-19941 Prevent forged DNSSEC-validated NXDOMAIN responses.

 - CVE-2026-19666 DNS64 with break-dnssec could cause an assertion failure.

 - CVE-2026-19667 Reject negative cache records that do not fit in a
   dns_rdata_t.

 - CVE-2026-19662 Prevent resolver crash with cached DNSSEC proofs.

 - CVE-2026-75029 Discard repeated SOA, CNAME, and DNAME records when
   parsing DNS messages.

 - CVE-2026-77692 Fix an unauthenticated crash on HTTPS using SIG(0)

 - CVE-2026-81736 Cached HTTPS/SVCB aliases could exhaust resolver CPU.

 - CVE-2026-76163 Prevent TKEY queries from terminating named without global
   options.

 - CVE-2026-78301 Out-of-zone records in a zone database could be served as
   authoritative.

 - CVE-2026-80274 Crash on wildcard answers carrying both NSEC and NSEC3
   proofs.

 - CVE-2026-81563 Following HTTPS/SVCB aliases could leak resolver cache
   memory.

Complete upstream changelog is available at
https://ftp.isc.org/isc/bind9/9.20.29/doc/arm/html/changelog.html

Signed-off-by: Noah Meyerhans <frodo@morgul.net>
@nmeyerhans

Copy link
Copy Markdown
Contributor Author

The CI failures seem unrelated to these changes.

@BKPepe
BKPepe merged commit 7992657 into openwrt:master Sep 18, 2026
11 of 14 checks passed
@BKPepe

BKPepe commented Sep 18, 2026

Copy link
Copy Markdown
Member

Backported to:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants