[El-errata] ELSA-2026-75577 Important: Oracle Linux 10 bind security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Mon Oct 5 18:15:56 UTC 2026
Oracle Linux Security Advisory ELSA-2026-75577
http://linux.oracle.com/errata/ELSA-2026-75577.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
bind-9.18.33-15.0.1.el10_2.12.x86_64.rpm
bind-chroot-9.18.33-15.0.1.el10_2.12.x86_64.rpm
bind-devel-9.18.33-15.0.1.el10_2.12.x86_64.rpm
bind-dnssec-utils-9.18.33-15.0.1.el10_2.12.x86_64.rpm
bind-doc-9.18.33-15.0.1.el10_2.12.noarch.rpm
bind-libs-9.18.33-15.0.1.el10_2.12.x86_64.rpm
bind-license-9.18.33-15.0.1.el10_2.12.noarch.rpm
bind-utils-9.18.33-15.0.1.el10_2.12.x86_64.rpm
aarch64:
bind-9.18.33-15.0.1.el10_2.12.aarch64.rpm
bind-chroot-9.18.33-15.0.1.el10_2.12.aarch64.rpm
bind-devel-9.18.33-15.0.1.el10_2.12.aarch64.rpm
bind-dnssec-utils-9.18.33-15.0.1.el10_2.12.aarch64.rpm
bind-doc-9.18.33-15.0.1.el10_2.12.noarch.rpm
bind-libs-9.18.33-15.0.1.el10_2.12.aarch64.rpm
bind-license-9.18.33-15.0.1.el10_2.12.noarch.rpm
bind-utils-9.18.33-15.0.1.el10_2.12.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/bind-9.18.33-15.0.1.el10_2.12.src.rpm
Related CVEs:
CVE-2026-19666
CVE-2026-19667
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736
Description of changes:
[9.18.33-15.0.1.el10_2.12]
- Hard require needed openssl-libs [Orabug: 38742109]
- Fix warning when changing device file permissions [Orabug: 36518580]
[32:9.18.33-15.12]
- Prevent assertion failure in dns64 mode with break-dnssec yes (CVE-2026-19666)
- Prevent memory leak on following HTTPS/SVCB RR (CVE-2026-81563)
- Prevent crash on wildcard responses containing both NSEC and NSEC3 proofs (CVE-2026-80274)
- Reject oversized negative cached records early (CVE-2026-19667)
- Set limit to following HTTPS/SVCB aliases (CVE-2026-81736)
[32:9.18.33-15.11]
- Add new root key 38696 into package files too (RHEL-252999)
[32:9.18.33-15.10]
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)
[32:9.18.33-15.9]
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)
[32:9.18.33-15.7]
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)
[32:9.18.33-15.6]
- Fix RRSIG label count validation for wildcard cache poisoning
(CVE-2026-11721)
[32:9.18.33-15.5]
- Fix RPZ name-too-long wildcard expansion (CVE-2026-11331)
[32:9.18.33-15.4]
- Fix assertion failure on malformed NSEC/NSEC3 responses
(CVE-2026-13204)
[32:9.18.33-15.2]
- Fix GSS-API resource leak (CVE-2026-3039)
- Invalid handling of CLASS != IN (CVE-2026-5946)
More information about the El-errata
mailing list