RHSA-2026:54071HighCVSS 8.6

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
August 12, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-10723 — bind: bind9: Incorrect acceptance of NSEC3 records CVE-2026-10822 — bind: bind9: Key Record using PRIVATEDNS algorithm may lead to exit CVE-2026-11331 — bind9: bind: Potential wildcard CNAME RPZ policy bypass CVE-2026-11622 — bind: bind9: Potential memory usage beyond configured limits CVE-2026-11721 — bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards CVE-2026-12617 — bind: bind9: Record ordering based unexpected exit with CNAME or DNAME CVE-2026-13204 — bind: bind9: Unexpected exit with NSEC and NSEC3 both present CVE-2026-13321 — bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field

🎯 Affected products5

  • Red Hat Hardened Images
  • bind-main@aarch64 as a component of Red Hat Hardened Images
  • bind-main@noarch as a component of Red Hat Hardened Images
  • bind-main@src as a component of Red Hat Hardened Images
  • bind-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Upgrade to the patched release most closely related to your current version of BIND 9: - 9.20.26 - 9.21.24 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. - 9.20.26-S1

🔗 References (12)