<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages/net/bind/patches, branch master</title>
<subtitle>Mirror of packages feed</subtitle>
<id>https://git-03.infra.openwrt.org/feed/packages/atom?h=master</id>
<link rel='self' href='https://git-03.infra.openwrt.org/feed/packages/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/'/>
<updated>2026-07-24T08:50:58Z</updated>
<entry>
<title>bind: bump to 9.20.26</title>
<updated>2026-07-24T08:50:58Z</updated>
<author>
<name>Noah Meyerhans</name>
</author>
<published>2026-07-23T13:18:15Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=81d81033e6a278663c6e0414f0ec07d37b1141bd'/>
<id>urn:sha1:81d81033e6a278663c6e0414f0ec07d37b1141bd</id>
<content type='text'>
Fixes several security issues:
 - CVE-2026-11331 Fix handling of rpz CNAME expansion that returns name too long.
 - CVE-2026-11721 Invalid signed wildcard records were being accepted.
 - CVE-2026-13321 Fix DNSSEC validation bypass via out-of-zone NSEC Next Field.
 - CVE-2026-10723 Correct verification of NSEC3 signer name.
 - CVE-2026-12617 Do no assert for some specifics CNAME and DNAME queries.
 - CVE-2026-10822 Malformed DNSKEY records could trigger an assertion.
 - CVE-2026-11605 Prevent excessive validation work from crafted negative responses.
 - CVE-2026-11622 Prevent cache exhaustion under sustained attack.

Full release notes are available upstream at
https://ftp.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html

Signed-off-by: Noah Meyerhans &lt;frodo@morgul.net&gt;
</content>
</entry>
<entry>
<title>bind: bump to 9.20.23</title>
<updated>2026-05-29T13:25:01Z</updated>
<author>
<name>Noah Meyerhans</name>
</author>
<published>2026-05-25T15:09:01Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=2394fbf0608f4ce09c070d5b20c7176123871f39'/>
<id>urn:sha1:2394fbf0608f4ce09c070d5b20c7176123871f39</id>
<content type='text'>
Resolves several security issues:

- CVE-2026-3592: Limit resolver server list size.
- CVE-2026-3039: Fix GSS-API resource leak.
- CVE-2026-5950: Avoid unbounded recursion loop.
- CVE-2026-5947: Fix crash in resolver when SIG(0)-signed responses are
  received under load.
- CVE-2026-3593: Add system test for HTTP/2 SETTINGS frame flood.
- CVE-2026-5946: Disable recursion, UPDATE, and NOTIFY for non-IN views.

Complete list of changes is available upstream at
https://ftp.isc.org/isc/bind9/9.20.23/doc/arm/html/changelog.html

Signed-off-by: Noah Meyerhans &lt;frodo@morgul.net&gt;
</content>
</entry>
<entry>
<title>bind: bump to 9.20.21</title>
<updated>2026-03-31T11:42:09Z</updated>
<author>
<name>Noah Meyerhans</name>
</author>
<published>2026-03-28T15:31:50Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=d6d7d2325aac8ed2680470e3b56b2dca830efb53'/>
<id>urn:sha1:d6d7d2325aac8ed2680470e3b56b2dca830efb53</id>
<content type='text'>
Fixes several security issues:

- CVE-2026-1519 Fix unbounded NSEC3 iterations when validating
  referrals to unsigned delegations.
- CVE-2026-3104 Fix memory leaks in code preparing DNSSEC proofs of
  non-existence.
- CVE-2026-3119 Prevent a crash in code processing queries containing
  a TKEY record.
- CVE-2026-3591 Fix a stack use-after-return flaw in SIG(0) handling
  code.

Signed-off-by: Noah Meyerhans &lt;frodo@morgul.net&gt;
</content>
</entry>
<entry>
<title>bind: backport patch replace automatic empty zones</title>
<updated>2026-02-01T14:01:50Z</updated>
<author>
<name>Philip Prindeville</name>
</author>
<published>2025-12-10T21:50:48Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=505ca0a0d4b6949f4ebedf0b0c31c18eeebf521c'/>
<id>urn:sha1:505ca0a0d4b6949f4ebedf0b0c31c18eeebf521c</id>
<content type='text'>
The RFC-1918 zones are automatically synthesized locally by bind
to avoid forwarding queries about them to root nameservers.  As
a result, we can't easily replace them with rndc addzone on the
fly.  We need this for DHCP integration.

Signed-off-by: Philip Prindeville &lt;philipp@redfish-solutions.com&gt;
</content>
</entry>
<entry>
<title>bind: bump to 9.17.12</title>
<updated>2021-04-29T19:39:46Z</updated>
<author>
<name>Noah Meyerhans</name>
</author>
<published>2021-04-29T16:05:26Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=ccb1e8923e6e0269e2443c37362b2b27c121d956'/>
<id>urn:sha1:ccb1e8923e6e0269e2443c37362b2b27c121d956</id>
<content type='text'>
Fixes the following security issues:

* CVE-2021-25215 - named crashed when a DNAME record placed in the ANSWER
                   section during DNAME chasing turned out to be the final
                   answer to a client query.
* CVE-2021-25214 - Insufficient IXFR checks could result in named serving a
                   zone without an SOA record at the apex, leading to a
                   RUNTIME_CHECK assertion failure when the zone was
                   subsequently refreshed. This has been fixed by adding an
                   owner name check for all SOA records which are included
                   in a zone transfer.

Signed-off-by: Noah Meyerhans &lt;frodo@morgul.net&gt;
</content>
</entry>
<entry>
<title>bind: update to 9.17.11</title>
<updated>2021-03-22T03:38:25Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2021-03-20T22:21:51Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=dd64cb713bc3d08b94b544d95dd22151f0e71394'/>
<id>urn:sha1:dd64cb713bc3d08b94b544d95dd22151f0e71394</id>
<content type='text'>
Backport upstream OpenSSL deprecated API patch.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
</content>
</entry>
<entry>
<title>bind: bump to 9.17.9</title>
<updated>2021-01-29T17:10:31Z</updated>
<author>
<name>Noah Meyerhans</name>
</author>
<published>2021-01-25T05:23:10Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=437e131fe0814a98415592b6275677c7e5b5d255'/>
<id>urn:sha1:437e131fe0814a98415592b6275677c7e5b5d255</id>
<content type='text'>
Drop obsolete patches

 - 001-no-tests.patch
 - 002-fix-cross-compilation.patch

Move several user-executable binaries from /usr/sbin to /usr/bin per
upstream.

Signed-off-by: Noah Meyerhans &lt;frodo@morgul.net&gt;
</content>
</entry>
<entry>
<title>bind: update to version 9.16.8</title>
<updated>2020-10-31T13:39:05Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2020-10-31T12:50:16Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=d442033941b9aa7c9086305099ed6111b86a2bcf'/>
<id>urn:sha1:d442033941b9aa7c9086305099ed6111b86a2bcf</id>
<content type='text'>
- DNS Flag Day 2020
(default EDNS buffer size changed from 4096 to 1232 bytes)

-- Added patch, which should be part of the next release
It fixes an issue while cross-compilation (I linked it in the commit
message with issue link)

Signed-off-by: Josef Schlehofer &lt;pepe.schlehofer@gmail.com&gt;
</content>
</entry>
<entry>
<title>bind: update to 9.14.3</title>
<updated>2019-06-26T23:25:44Z</updated>
<author>
<name>Deng Qingfang</name>
</author>
<published>2019-06-26T10:14:19Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=868f29d4ee61205e65994f67f23a02198a9dea33'/>
<id>urn:sha1:868f29d4ee61205e65994f67f23a02198a9dea33</id>
<content type='text'>
Fixed CVE-2019-6471

ChangeLog: https://ftp.isc.org/isc/bind9/9.14.3/CHANGES

Signed-off-by: Deng Qingfang &lt;dengqf6@mail2.sysu.edu.cn&gt;
</content>
</entry>
<entry>
<title>bind: update to 9.14.2</title>
<updated>2019-05-18T16:16:41Z</updated>
<author>
<name>Deng Qingfang</name>
</author>
<published>2019-05-16T15:43:51Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/feed/packages/commit/?id=cc66a24a4e1010439254751e415cc42566fed01a'/>
<id>urn:sha1:cc66a24a4e1010439254751e415cc42566fed01a</id>
<content type='text'>
BIND now requires POSIX thread and IPv6 support to build

Add filter-AAAA plugin

Remove unrecognized options

Remove patch that no longer needed
- 002-autoconf-ar-fix.patch

Signed-off-by: Deng Qingfang &lt;dengqf6@mail2.sysu.edu.cn&gt;
</content>
</entry>
</feed>
