Internet Systems Consortium (ISC) has released BIND 9.20.29, an Extended Support Version update that addresses 14 security vulnerabilities affecting the named DNS server and recursive resolver. The release fixes DNSSEC validation bypasses, cache-poisoning risks, remotely triggerable crashes, and resource-exhaustion conditions that could disrupt DNS availability or weaken validated answers. BIND 9.20.29 Fixes 14 Security Flaws An attacker capable of injecting responses can undermine secure delegation, allowing for forged unsigned answers and cache poisoning.
CVE-2026-81736 limits CPU-intensive processing of large, interlinked HTTPS and SVCB alias records, while CVE-2026-81563 fixes a cache-memory leak involving alias targets with more than 13 records.
These include CVE-2026-19666, which affects recursive resolvers with dns64 configured and break-dnssec set to yes; CVE-2026-19667, involving malformed negative cache entries; and CVE-2026-19662, a race condition in cached DNSSEC NOQNAME proofs. ISC also addressed crashes related to repeated SOA, CNAME, and DNAME records; SIG(0)-authenticated HTTPS queries; TKEY queries without global options; and wildcard responses containing both NSEC and NSEC3 proofs. BIND now requires TSIG authentication on every message in incoming AXFR and IXFR transfers, closing a gap where unsigned transfer messages could be processed before a subsequent signature authenticated them.
Administrators should focus on upgrading Internet-facing recursive resolvers, DNSSEC-validating infrastructure, servers using DNS64, and deployments that allow queries from untrusted clients.








.jpg?width=1280&auto=webp&quality=80&disable=upscale)


