From: Evan Hunt Date: Thu, 2 Jul 2026 05:51:01 +0000 (+0000) Subject: [CVE-2026-10723] sec: usr: Correct verification of NSEC3 signer name X-Git-Tag: v9.21.24~5 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=66822f731d2d1c36b70cc1ae540d4e9d6406e277;p=thirdparty%2Fbind9.git [CVE-2026-10723] sec: usr: Correct verification of NSEC3 signer name BIND 9 accepted child-zone NSEC3 records where the first label equals the hash of the parent zone as valid parent-zone closest encloser proofs. This has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue. Closes isc-projects/bind9#5874 Merge branch '5874-confidential-nsec3-apex-hash-bypass' into 'security-main' See merge request isc-private/bind9!1082 --- 66822f731d2d1c36b70cc1ae540d4e9d6406e277