Vulnerabilities & PatchesEmerging1 src
BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and Denial-of-Service Attacks
Internet Systems Consortium (ISC) has released BIND 9. 20. 29, an Extended Support Version update that fixes 14 security vulnerabilities affecting the named DNS server and recursive resolver.
The release addresses DNSSEC validation bypasses, cache-poisoning risks, remotely triggerable crashes, and resource-exhaustion conditions that could disrupt DNS availability or weaken trust in validated answers.
BIND 9. 20. 29 follows the withdrawn 9. 20. 28 release and is the recommended upgrade for affected 9. 20 deployments.
BIND 9. 20. 29 Fixes 14 Security Flaws
Two medium-severity flaws stand out because they can undermine DNSSEC protections. CVE-2026-77119 allows a validating resolver to accept a validly signed NSEC3 record from an unrelated sibling zone as an insecurity proof.