[CLSA-2026:1787731848] Fix CVE(s): CVE-2025-40778, CVE-2025-8677, CVE-2026-1519
Type:
security
Severity:
Important
Release date:
2026-08-26 08:11:07 UTC
Description:
* SECURITY UPDATE: cache poisoning via unsolicited answer records - debian/patches/CVE-2025-40778.patch: require the NS RRset owner name to be an ancestor of the queried name, restrict cached glue to the NS bailiwick apex, and retry unsigned DNAME responses over TCP - CVE-2025-40778 * SECURITY UPDATE: excessive NSEC3 iterations CPU denial of service during insecure delegation validation - debian/patches/CVE-2026-1519.patch: cap NSEC3 iterations at DNS_NSEC3_MAXITERATIONS (150) in isdelegation() and skip already-trusted rdatasets during the insecurity proof - CVE-2026-1519
Updated packages:
  • bind9_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:53f1f681bc25ad4fc273f0ee6c74f32786b35e24
  • bind9-doc_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_all.deb
    sha:95daf57a66d174eeb47f16fd342f0cac8a6bdb67
  • bind9-host_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:bc9c3ca983f90a7140ea500cdd1d8fc0b0417f84
  • bind9utils_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:be3219a88ec4440ac7fb89be884f783ed303ea2e
  • dnsutils_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:93fd6939b9c56594c4f68e2debbc6e1c86a9ae02
  • libbind-dev_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:ea8e0437d01870ef71922fdbcc3084464ecdf3f8
  • libbind-export-dev_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:e3c6788e4d09078009f96af6b65f260ca8f21ce8
  • libbind9-160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:d8179b1fcc8a9f965945b82423e059ad60c416cc
  • libdns-export1100_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:939300e6da92ca01f537db710a443e23c3987f91
  • libdns1100_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:4a7c8ab720a1251e38d9a3eee1b6c93ea8464feb
  • libirs-export160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:2c30e4040dfee8035f95d56d033d6062ec81dd88
  • libirs160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:39072ff9562e063d3b298cbb1373f1734b5e33f0
  • libisc-export169_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:b1c3ffa5dc8de3dc8c720825a8f2be4e37943ed4
  • libisc169_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:ef5f16c236de84a515b3ec16e3c5a8568fc7598d
  • libisccc-export160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:c1bb106dc8a1b4b0bc8e136abf92b4b6757e922e
  • libisccc160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:5d9307f4e3cdcde406675a8a756c8dd81464cbed
  • libisccfg-export160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:16f6dd083ebb7ac1e818b91629aab5e58c0d8ae4
  • libisccfg160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:100ba636aa0f25395a78054b48d25fa9bdcd702a
  • liblwres160_9.11.3+dfsg-1ubuntu1.18+tuxcare.els9_amd64.deb
    sha:6ae9a29feee1424452f1ea02ab273d0a34921a35
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.