ISC has released BIND versions 9.20.26 and 9.21.24 to address critical vulnerabilities in the named daemon, particularly concerning DNSSEC validation bypasses and potential remote code execution. Users running older versions than 9.20.20 are urged to upgrade immediately to prevent cache poisoning and memory exhaustion issues. The updates include fixes for several CVEs, ensuring that resolvers validate signer names to maintain trust chains and prevent memory overload from malicious queries. While version 9.20.26 is stable and ready for production, 9.21.24 remains a testing release and should not be deployed in live environments
BIND 9.20.26 and 9.21.24 Released to Patch Critical DNSSEC Flaws
ISC has officially released BIND 9.20.26 and 9.21.24 to patch a severe cluster of vulnerabilities in the named daemon. The stable branch update targets critical DNSSEC validation bypasses, use-after-free flaws in DNS-over-HTTPS, and memory exhaustion bugs that could allow cache poisoning or remote code execution. Recursive resolvers and authoritative servers running versions older than 9.20.20 are sitting in the blast radius and need an immediate upgrade.
BIND 9.20.26 and 9.21.24 Released to Patch Critical DNSSEC Flaws @ Linux Compatible
