[CLSA-2026:1785886464] Fix CVE(s): CVE-2026-1519
Type:
security
Severity:
Important
Release date:
2026-08-04 23:34:34 UTC
Description:
* SECURITY UPDATE: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation (DNSSEC CPU denial of service) - debian/patches/CVE-2026-1519.patch: cap NSEC3 iterations at DNS_NSEC3_MAXITERATIONS (150) during the insecurity proof and treat the delegation as insecure when the limit is exceeded; skip re-verifying already-secure rdatasets in the negative-response and verify paths, in lib/dns/validator.c and lib/dns/include/dns/types.h. - CVE-2026-1519
CVEs fixed:
Updated packages:
  • bind9_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
    sha:95b8cce2f93220ad66355fa9bc5c4d0b7a2b62c5
  • bind9-dnsutils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
    sha:1b6f30603569a99ac0bac266ded2a0884e440dbb
  • bind9-doc_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_all.deb
    sha:35b48064f82679d01dda2a7a508ffcd277cc8e66
  • bind9-host_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
    sha:cd764a889f933a1dc7f02c0fdd5387e3d97d24e8
  • bind9-libs_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
    sha:c190da7b9691c0087cec0b801abcee413dc74f83
  • bind9-utils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_amd64.deb
    sha:df1031737f2d78ee10ca31dc7ac6e3cd0a2a0311
  • bind9utils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_all.deb
    sha:8186e7aaf20c5a9d6ae87200cd6a52bb8d4244af
  • dnsutils_9.18.30-0ubuntu0.20.04.2+tuxcare.els3_all.deb
    sha:6c0dcf731b3a105ff324896707b5de8ab4d0919f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.