BIND 9 accepted child-zone NSEC3 records where the first label equals the hash of the parent zone as valid parent-zone closest encloser proofs. This has been fixed.
ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue.
Closes isc-projects/bind9#5874
Merge branch '5874-confidential-nsec3-apex-hash-bypass' into 'security-main'
See merge request isc-private/bind9!1082