SUSE SLED15 / SLES15 Security Update : bind (SUSE-SU-2026:3426-1)

high Nessus Plugin ID 331433

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3426-1 advisory.

Upgrade to release 9.20.26.

Security issues fixed:

- CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
- CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected exit (bsc#1271983).
- CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
- CVE-2026-11605: unnecessary validation of DNSSEC signed records (bsc#1271985).
- CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986).
- CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).
- CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME (bsc#1271988).
- CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989).
- CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990).

Other updates and bugfixes:

- Release 9.20.26:
* Reclaim memory promptly when DNSSEC validations are canceled.
* Removed Features:
* Remove the secondary validator in query.c.
* Remove ineffective TCP fallback after repeated UDP timeouts.
* Feature Changes:
* Fall back to TCP on receipt of a UDP response with a mismatched query ID.
* Limit the number of glue records cached from a referral.
* Fix a resolver stall on a CNAME response to a DS query.
* Bug Fixes:
* Fix a bug in DNS UPDATE processing with inline-signing enabled.
* Properly detect private records before copying.
* Tighten referral DS acceptance.
* Don't synthesize negative responses with pending NSEC.
* Check that an NSEC signer is at or above the name to be validated.
* Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN.
* Fix a deny-answer-aliases configuration bypass issue.
* Reject external referrals from forwarders.
* Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode.
* Unvalidated opt-out NSEC3 could be accepted in insecurity proof.
* Check wildcard signer and NOQNAME signer match.
* Fix CNAME resolution failure caused by a cached SERVFAIL response.
* Reject unsupported RSA DNSKEY shapes during DNSSEC validation.
* Fix a bug in GeoIP2 string matching.
* Fix DNS-over-HTTPS (DoH) quota configuration issue.
* Truncated reply to a TSIG query no longer stalls the resolver.
* Ignore updates removing DNSKEY RRset with class ANY.
* Ignore 0-byte reads in the TCP read callback.
* Only print per-zone glue stats when zone-statistics is set to full.
* CDS/CDNSKEY records were not removed when re-configuring the server.
* Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB.
* Stop reusing outgoing TCP connections the peer has already closed.
* Fix DNSSEC validation failures for names under an apex DNAME.
* The resolver now removes other RRsets at the same name when caching a CNAME.
* Fix nxdomain-redirect combined with dns64.
* Fix DNS64 owner case after DNAME restart.
* Clear REDIRECT flag when it isn't needed.
* Disable output escaping in bind9.xsl.
* Fix crash on badly configured secondary signer.
* Fix a possible crash on concurrent TKEY DELETE for the same key.
* Reject RRSIG records covering meta-types.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected bind, bind-doc and / or bind-utils packages.

See Also

https://bugzilla.suse.com/1271982

https://bugzilla.suse.com/1271983

https://bugzilla.suse.com/1271984

https://bugzilla.suse.com/1271985

https://bugzilla.suse.com/1271986

https://bugzilla.suse.com/1271987

https://bugzilla.suse.com/1271988

https://bugzilla.suse.com/1271989

https://bugzilla.suse.com/1271990

https://lists.suse.com/pipermail/sle-updates/2026-July/048971.html

https://www.suse.com/security/cve/CVE-2026-10723

https://www.suse.com/security/cve/CVE-2026-10822

https://www.suse.com/security/cve/CVE-2026-11331

https://www.suse.com/security/cve/CVE-2026-11605

https://www.suse.com/security/cve/CVE-2026-11622

https://www.suse.com/security/cve/CVE-2026-11721

https://www.suse.com/security/cve/CVE-2026-12617

https://www.suse.com/security/cve/CVE-2026-13204

https://www.suse.com/security/cve/CVE-2026-13321

Plugin Details

Severity: High

ID: 331433

File Name: suse_SU-2026-3426-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/31/2026

Updated: 7/31/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.94

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-13321

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:bind-doc, p-cpe:/a:novell:suse_linux:bind-utils, p-cpe:/a:novell:suse_linux:bind

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/30/2026

Vulnerability Publication Date: 7/22/2026

Reference Information

CVE: CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321

IAVA: 2026-A-0764

SuSE: SUSE-SU-2026:3426-1