BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and Denial-of-Service Attacks
Brief
Internet Systems Consortium (ISC) has released BIND 9.
- 29, an Extended Support Version update that fixes 14 security vulnerabilities affecting the named DNS server and recursive resolver.
The release addresses DNSSEC validation bypasses, cache-poisoning risks, remotely triggerable crashes, and resource-exhaustion conditions that could disrupt DNS availability or weaken trust in validated answers.
BIND 9.
- 29 follows the withdrawn 9.
- 28 release and is the recommended upgrade for affected 9. 20 deployments.
BIND 9.
- 29 Fixes 14 Security Flaws
Two medium-severity flaws stand out because they can undermine DNSSEC protections. CVE-2026-77119 allows a validating resolver to accept a validly signed NSEC3 record from an unrelated sibling zone as an insecurity proof.
