Release date:
2026-08-04 23:34:34 UTC
Description:
* SECURITY UPDATE: Excessive NSEC3 iterations cause high CPU load during
insecure delegation validation (DNSSEC CPU denial of service)
- debian/patches/CVE-2026-1519.patch: cap NSEC3 iterations at
DNS_NSEC3_MAXITERATIONS (150) during the insecurity proof and treat the
delegation as insecure when the limit is exceeded; skip re-verifying
already-secure rdatasets in the negative-response and verify paths, in
lib/dns/validator.c and lib/dns/include/dns/types.h.
- CVE-2026-1519
Updated packages:
-
bind9_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
sha:95b8cce2f93220ad66355fa9bc5c4d0b7a2b62c5
-
bind9-dnsutils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
sha:1b6f30603569a99ac0bac266ded2a0884e440dbb
-
bind9-doc_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_all.deb
sha:35b48064f82679d01dda2a7a508ffcd277cc8e66
-
bind9-host_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
sha:cd764a889f933a1dc7f02c0fdd5387e3d97d24e8
-
bind9-libs_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
sha:c190da7b9691c0087cec0b801abcee413dc74f83
-
bind9-utils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
sha:df1031737f2d78ee10ca31dc7ac6e3cd0a2a0311
-
bind9utils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_all.deb
sha:8186e7aaf20c5a9d6ae87200cd6a52bb8d4244af
-
dnsutils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_all.deb
sha:6c0dcf731b3a105ff324896707b5de8ab4d0919f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.