Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4285-1 advisory.
- CVE-2026-19033: Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (bsc#1280430).
- CVE-2026-19662: qpcache NOQNAME proof use-after-free crashes recursive resolver (bsc#1280432).
- CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (bsc#1280433).
- CVE-2026-19667: Remote assertion failure via 16-bit length truncation in dns_ncache_add() (bsc#1280435).
- CVE-2026-19668: Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (bsc#1280436).
- CVE-2026-19941: checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (bsc#1280437).
- CVE-2026-75029: Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (bsc#1280438).
- CVE-2026-76163: named aborts on a TKEY query when the user configuration has no global options statement (bsc#1280439).
- CVE-2026-77119: NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (bsc#1280440).
- CVE-2026-77692: Unauthenticated remote crash of named via a single DoH SIG(0) request (bsc#1280441).
- CVE-2026-78301: Out-of-zone database nodes can become authoritative zone cuts (bsc#1280442).
- CVE-2026-80274: Validating resolver can abort while caching a mismatched NOQNAME proof (bsc#1280443).
- CVE-2026-81563: SVCB AliasMode additional-data error leaks qpcache references (bsc#1280444).
- CVE-2026-81736: Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (bsc#1280445).
Changes for bind:
Upgrade to release 9.20.29
New Features:
* Disclose active Negative Trust Anchors with Extended DNS Error 33.
Feature Changes:
* Reject oversized and malformed DNSKEY records up front.
* Speed up RPZ policy zone updates.
Bug Fixes:
* Prevent a crash when using both dns64 and filter-a.
* Stop passing UDP client addresses to update-policy external helpers.
* Missing required NSEC3 for delegation not detected.
* Tighten EUI48 and EUI64 text parsing.
* GeoIP ACL state could be stale or wrong after reload.
* Honor DNSSEC policy key tag ranges.
* Fix a double free in mdig when EDNS options are specified.
* Fix a crash when an IXFR falls back to AXFR with updates still pending.
* Fix DS requests to parental agents over TLS.
* Fix the rndc-confgen -q (quiet) option.
* Enforce query ACLs for redirect zones and searched DLZs.
* Check asnum validity in GeoIP ACLs.
* Fix a crash on remote-servers lists that reference themselves.
* A record from outside a response policy zone could crash named.
* Invalid key-store configuration could abort the DNSSEC tools.
* NSEC signature set could bypass the secure-delegation check.
* Fix a possible nsupdate issue when using GSS-TSIG.
* Fix a crash with a single-element geoip sortlist.
* Prevent out-of-bailiwick CNAMEs from evicting cached records.
* Restore periodic cleanup of stale resolver address data.
* Fix named-checkconf/named crash with malformed key name.
* Prevent resolver crashes while processing DNS over TCP.
* Ensure NSEC authority does not cross zonecut boundary.
* Treat an unusable NSEC3 chain as a verification failure.
* Treat non-canonical RPZ prefixes as any other failure.
* Negative caching stopped working with stale-answer-client-timeout set to 0.
* An unterminated OpenSSL private-key Label: field could be read past its parser buffer.
* Restore SMF support on Solaris and illumos.
* Fix compilation on GNU/Hurd.
* dig +yaml was producing invalid YAML when a lookup failed.
* Properly prevent TSIG generation command line injection attacks.
* Fix a potential heap bounds overflow write in dnssec-signzone.
* Fix crashes on invalid DNSTAP input in dnstap-read.
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected bind, bind-doc and / or bind-utils packages.
Plugin Details
File Name: suse_SU-2026-4285-1.nasl
Agent: unix
Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:P
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:bind-doc, p-cpe:/a:novell:suse_linux:bind-utils, p-cpe:/a:novell:suse_linux:bind
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 9/22/2026
Vulnerability Publication Date: 9/16/2026
Reference Information
CVE: CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736
IAVA: 2026-A-1029
SuSE: SUSE-SU-2026:4285-1