[El-errata] ELSA-2026-75578 Important: Oracle Linux 9 bind9.18 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Oct 8 13:19:35 UTC 2026


Oracle Linux Security Advisory ELSA-2026-75578

http://linux.oracle.com/errata/ELSA-2026-75578.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
bind9.18-9.18.29-14.el9_8.10.x86_64.rpm
bind9.18-chroot-9.18.29-14.el9_8.10.x86_64.rpm
bind9.18-devel-9.18.29-14.el9_8.10.i686.rpm
bind9.18-devel-9.18.29-14.el9_8.10.x86_64.rpm
bind9.18-dnssec-utils-9.18.29-14.el9_8.10.x86_64.rpm
bind9.18-doc-9.18.29-14.el9_8.10.noarch.rpm
bind9.18-libs-9.18.29-14.el9_8.10.i686.rpm
bind9.18-libs-9.18.29-14.el9_8.10.x86_64.rpm
bind9.18-utils-9.18.29-14.el9_8.10.x86_64.rpm

aarch64:
bind9.18-9.18.29-14.el9_8.10.aarch64.rpm
bind9.18-chroot-9.18.29-14.el9_8.10.aarch64.rpm
bind9.18-devel-9.18.29-14.el9_8.10.aarch64.rpm
bind9.18-dnssec-utils-9.18.29-14.el9_8.10.aarch64.rpm
bind9.18-doc-9.18.29-14.el9_8.10.noarch.rpm
bind9.18-libs-9.18.29-14.el9_8.10.aarch64.rpm
bind9.18-utils-9.18.29-14.el9_8.10.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/bind9.18-9.18.29-14.el9_8.10.src.rpm

Related CVEs:

CVE-2026-19666
CVE-2026-19667
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736




Description of changes:

[32:9.18.29-14.10]
- Prevent assertion failure in dns64 mode with break-dnssec yes (CVE-2026-19666)
- Prevent memory leak on following HTTPS/SVCB RR (CVE-2026-81563)
- Prevent crash on wildcard responses containing both NSEC and NSEC3 proofs (CVE-2026-80274)
- Reject oversized negative cached records early (CVE-2026-19667)
- Set limit to following HTTPS/SVCB aliases (CVE-2026-81736)

[32:9.18.29-14.9]
- Add new root key 38696 into package files (RHEL-255223)
- Update built-in anchors in delv and named




More information about the El-errata mailing list