Home / Sep 18, 2026 / Story
0
#9 The Hacker News general September 17, 2026 at 08:00 UTC

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

By [email protected] (The Hacker News)

AI Summary

ISC released BIND 9.20.29 and 9.21.26 on September 16 to fix 14 security flaws, including an unauthenticated crash vulnerability affecting any BIND server configured with DNS-over-HTTPS — a single malformed SIG record is sufficient to kill the named process. Additionally, CVE-2026-81642 is a critical heap overflow in the DNSSEC validator in Unbound before version 1.26.1 that enables RCE via a malicious DNS zone.

Relevance score: 77.0/100

# More from September 18