From b34e601b7e4a3d0166e05162fcb1dc8f32ac5079 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Micha=C5=82=20K=C4=99pie=C5=84?= Date: Fri, 13 Mar 2026 21:48:14 +0100 Subject: [PATCH] Prepare release notes for BIND 9.18.47 --- doc/arm/notes.rst | 1 + doc/notes/notes-9.18.47.rst | 32 ++++++++++++++++++++++++++++++++ 2 files changed, 33 insertions(+) create mode 100644 doc/notes/notes-9.18.47.rst diff --git a/doc/arm/notes.rst b/doc/arm/notes.rst index 99f26debbd..fe5d4d28ef 100644 --- a/doc/arm/notes.rst +++ b/doc/arm/notes.rst @@ -45,6 +45,7 @@ The list of known issues affecting the latest version in the 9.18 branch can be found at https://gitlab.isc.org/isc-projects/bind9/-/wikis/Known-Issues-in-BIND-9.18 +.. include:: ../notes/notes-9.18.47.rst .. include:: ../notes/notes-9.18.46.rst .. include:: ../notes/notes-9.18.45.rst .. include:: ../notes/notes-9.18.44.rst diff --git a/doc/notes/notes-9.18.47.rst b/doc/notes/notes-9.18.47.rst new file mode 100644 index 0000000000..23c87f87cd --- /dev/null +++ b/doc/notes/notes-9.18.47.rst @@ -0,0 +1,32 @@ +.. Copyright (C) Internet Systems Consortium, Inc. ("ISC") +.. +.. SPDX-License-Identifier: MPL-2.0 +.. +.. This Source Code Form is subject to the terms of the Mozilla Public +.. License, v. 2.0. If a copy of the MPL was not distributed with this +.. file, you can obtain one at https://mozilla.org/MPL/2.0/. +.. +.. See the COPYRIGHT file distributed with this work for additional +.. information regarding copyright ownership. + +Notes for BIND 9.18.47 +---------------------- + +Security Fixes +~~~~~~~~~~~~~~ + +- [CVE-2026-1519] Fix unbounded NSEC3 iterations when validating + referrals to unsigned delegations. + + DNSSEC-signed zones may contain high iteration-count NSEC3 records, + which prove that certain delegations are insecure. Previously, a + validating resolver encountering such a delegation processed these + iterations up to the number given, which could be a maximum of 65,535. + This has been addressed by introducing a processing limit, set at 150. + Now, if such an NSEC3 record is encountered, the delegation will be + treated as insecure. + + ISC would like to thank Samy Medjahed/Ap4sh for bringing this + vulnerability to our attention. :gl:`#5708` + +