ALAS2023-2026-3137


Amazon Linux 2023 Security Advisory: ALAS2023-2026-3137
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
Severity: Important

Issue Overview:

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-19033)

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-19662)

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-19666)

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-19667)

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-19941)

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly lead to other memory attack vectors.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-75029)

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-zone delegation. On a server that also provides recursion BIND can follow this locally sourced cut and cache attacker-supplied data, affecting names outside the configured zone. This situation persists as long as the malformed zone remains in the zone database.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-78301)

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-80274)

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-81563)

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1. (CVE-2026-81736)


Affected Packages:

bind


Issue Correction:
Run dnf update bind --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3137 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    bind-utils-debuginfo-9.18.50-1.amzn2023.0.3.aarch64
    bind-libs-9.18.50-1.amzn2023.0.3.aarch64
    bind-debugsource-9.18.50-1.amzn2023.0.3.aarch64
    bind-dnssec-utils-debuginfo-9.18.50-1.amzn2023.0.3.aarch64
    bind-dnssec-utils-9.18.50-1.amzn2023.0.3.aarch64
    bind-debuginfo-9.18.50-1.amzn2023.0.3.aarch64
    bind-devel-9.18.50-1.amzn2023.0.3.aarch64
    bind-9.18.50-1.amzn2023.0.3.aarch64
    bind-chroot-9.18.50-1.amzn2023.0.3.aarch64
    bind-utils-9.18.50-1.amzn2023.0.3.aarch64
    bind-libs-debuginfo-9.18.50-1.amzn2023.0.3.aarch64

noarch:
    bind-license-9.18.50-1.amzn2023.0.3.noarch
    bind-doc-9.18.50-1.amzn2023.0.3.noarch

src:
    bind-9.18.50-1.amzn2023.0.3.src

x86_64:
    bind-utils-debuginfo-9.18.50-1.amzn2023.0.3.x86_64
    bind-libs-debuginfo-9.18.50-1.amzn2023.0.3.x86_64
    bind-chroot-9.18.50-1.amzn2023.0.3.x86_64
    bind-debugsource-9.18.50-1.amzn2023.0.3.x86_64
    bind-9.18.50-1.amzn2023.0.3.x86_64
    bind-utils-9.18.50-1.amzn2023.0.3.x86_64
    bind-dnssec-utils-9.18.50-1.amzn2023.0.3.x86_64
    bind-devel-9.18.50-1.amzn2023.0.3.x86_64
    bind-dnssec-utils-debuginfo-9.18.50-1.amzn2023.0.3.x86_64
    bind-debuginfo-9.18.50-1.amzn2023.0.3.x86_64
    bind-libs-9.18.50-1.amzn2023.0.3.x86_64