importantSYS.SOURCE: The Hacker News• 2026-09-17T13:30:29+05:30
BIND 9 Security Update Resolves 14 Vulnerabilities, Including DoH Crash Flaw
BIND 9's latest update addresses 14 security flaws, including a critical unauthenticated crash vulnerability affecting DNS-over-HTTPS (DoH) servers. The fixes apply to versions 9.20.29 and 9.21.26, with warnings about ongoing support for older branches and potential risks for unpatched systems.
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).
A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG
*** END OF TRANSMISSION ***