From: Mark Andrews Date: Fri, 10 Apr 2026 08:07:49 +0000 (+1000) Subject: [9.18] fix: usr: Fix zone verification of NSEC3 signed zones X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=3a2e16ae658dc0bc2f40185e0aa3d7832a93fece;p=thirdparty%2Fbind9.git [9.18] fix: usr: Fix zone verification of NSEC3 signed zones Previously, when computing the compressed bitmap during verification of an NSEC3-signed zone, an undersized buffer was used that resulted in an out-of-bounds write if there were too many active windows in the bitmap. This impacted mirror zones which are NSEC3-signed, `dnssec-signzone` and `dnssec-verifyzone`. This has been fixed. Closes #5834 Backport of MR !11804 Merge branch 'backport-5834-fix-cbm-size-9.18' into 'bind-9.18' See merge request isc-projects/bind9!11834 --- 3a2e16ae658dc0bc2f40185e0aa3d7832a93fece