[El-errata] ELSA-2026-54509 Important: Oracle Linux 8 bind9.16 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Aug 14 13:06:26 UTC 2026


Oracle Linux Security Advisory ELSA-2026-54509

http://linux.oracle.com/errata/ELSA-2026-54509.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bind9.16-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-chroot-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-devel-9.16.23-0.22.el8_10.12.i686.rpm
bind9.16-devel-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-doc-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-libs-9.16.23-0.22.el8_10.12.i686.rpm
bind9.16-libs-9.16.23-0.22.el8_10.12.x86_64.rpm
bind9.16-license-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-utils-9.16.23-0.22.el8_10.12.x86_64.rpm
python3-bind9.16-9.16.23-0.22.el8_10.12.noarch.rpm

aarch64:
bind9.16-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-chroot-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-devel-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-dnssec-utils-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-doc-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-libs-9.16.23-0.22.el8_10.12.aarch64.rpm
bind9.16-license-9.16.23-0.22.el8_10.12.noarch.rpm
bind9.16-utils-9.16.23-0.22.el8_10.12.aarch64.rpm
python3-bind9.16-9.16.23-0.22.el8_10.12.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/bind9.16-9.16.23-0.22.el8_10.12.src.rpm

Related CVEs:

CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321




Description of changes:

[32:9.16.23-0.22.12]
- Fix NSEC3 signer validation (CVE-2026-10723)
- Resolves: RHEL-213499

[32:9.16.23-0.22.11]
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)
- Resolves: RHEL-213313

[32:9.16.23-0.22.10]
- Fix CVE-2026-11622: reference-counted DNS cache slab headers
- Resolves: RHEL-213396

[32:9.16.23-0.22.9]
- Fix CVE-2026-11721: RRSIG labels validation and out-of-zone signing
- Add new unit test
- Resolves: RHEL-213406

[32:9.16.23-0.22.8]
- Fix RPZ name-too-long wildcard expansion (CVE-2026-11331)
- Add upstream rpz system test
- Resolves: RHEL-213478

[32:9.16.23-0.22.7]
- Fix CVE-2026-13204: ensure NSEC/NSEC3 has matching RRSIG
- Resolves: RHEL-213478




More information about the El-errata mailing list