From: Mark Andrews Date: Mon, 22 Jun 2026 11:27:01 +0000 (+1000) Subject: [CVE-2026-11721] sec: usr: Invalid signed wildcard records were being accepted X-Git-Tag: v9.21.24~12 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=2dbb7461ce35baa2663e169a5b8d93edd8457c54;p=thirdparty%2Fbind9.git [CVE-2026-11721] sec: usr: Invalid signed wildcard records were being accepted Signed wildcard responses in which the Labels field in the `RRSIG` record was less than the number of labels in the Signer Name field were being incorrectly accepted. This in turn broke `synth-from-dnssec`, which depends on such records being correctly validated. This has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention. Closes https://gitlab.isc.org/isc-projects/bind9/-/issues/5871 Merge branch '5871-confidential-check-rrsig-labels-vs-signer' into 'security-main' See merge request isc-private/bind9!991 --- 2dbb7461ce35baa2663e169a5b8d93edd8457c54