]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
regen v9_10
authorTinderbox User <tbox@isc.org>
Thu, 29 Dec 2016 05:06:48 +0000 (05:06 +0000)
committerTinderbox User <tbox@isc.org>
Thu, 29 Dec 2016 05:06:48 +0000 (05:06 +0000)
44 files changed:
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nsupdate.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html

index 56a42b5f5d559dd686ec75da013c44edd7b9fe73..2d06932d9b2b2b021e6d3e4134077ac744bc0798 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 63206bbb6b9e2a381d787d598b4da85ef2afb223..0369cdd44c4ad337d32b17dd6286dbbd3ac993f6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 6fe9592e6da2204f9ef94496476dd14b45b894c0..0cc864225eec3f4eb48bfd66dc69c3c59e02108e 100644 (file)
@@ -768,6 +768,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 39d36fdcaed2c5e0b4cf12b8e2c152a91ea97d26..0b49abc05f249cc092b77d3497bf43742e3c66f2 100644 (file)
@@ -2498,6 +2498,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 0b2168902a4d617c4e58972998adbf0518591ce6..48307b863bdd14b197121a5beff473345240b963 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index e573a15038baf3fbc78f480516d2d0ec7c8576ec..d521b566f58f839d71e4609ab20bed56d254da0b 100644 (file)
@@ -13790,6 +13790,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index a91c83c44b23b2999cf75a339916127e7fd3acad..f8039fb68522c0ac85d2c7c92b0ef2cb8f8f8b77 100644 (file)
@@ -262,6 +262,6 @@ zone "example.com" {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 912820e1778e191cca92dbc51b363ff0e39eea6e..8213331ea62ed52b3b0f45b8f1594a5c1ad0a4e4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 0cedf08cf546ddf4d1213297b5a46030b50d44b3..b8f3d3e34443a31b2f6170350082f475051ff3d7 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.4</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.5b1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_port">Porting Changes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
 </dl></dd>
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.10.4</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.10.5b1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes significant changes since the last
-      production release of BIND on the corresponding major release
-      branch.
-      Please see the CHANGES file for a further list of bug fixes and
-      other changes.
+      This document summarizes changes since the last production
+      release on the BIND 9.10 branch.
+      Please see the <code class="filename">CHANGES</code> file for a further
+      list of bug fixes and other changes.
     </p>
   </div>
 
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
        <p>
-         Added the ability to specify the maximum number of records
-         permitted in a zone (max-records #;).  This provides a mechanism
-         to block overly large zone transfers, which is a potential risk
-         with slave zones from other parties, as described in CVE-2016-6170.
-         [RT #42143]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger a assertion when rendering a
-         message using a specially crafted request. This flaw is
-         disclosed in CVE-2016-2776. [RT #43139]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-        getrrsetbyname with a non absolute name could trigger an
-        infinite recursion bug in lwresd and named with lwres
-        configured if when combined with a search list entry the
-        resulting name is too long.  This flaw is disclosed in
-        CVE-2016-2775. [RT #42694]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Duplicate EDNS COOKIE options in a response could trigger
-         an assertion failure. This flaw is disclosed in CVE-2016-2088.
-         [RT #41809]
+         <span class="command"><strong>named</strong></span> could mishandle authority sections
+         with missing RRSIGs, triggering an assertion failure. This
+         flaw is disclosed in CVE-2016-9444. [RT #43632]
        </p>
       </li>
 <li class="listitem">
        <p>
-         The resolver could abort with an assertion failure due to
-         improper DNAME handling when parsing fetch reply
-         messages. This flaw is disclosed in CVE-2016-1286. [RT #41753]
+         <span class="command"><strong>named</strong></span> mishandled some responses where
+         covering RRSIG records were returned without the requested
+         data, resulting in an assertion failure. This flaw is
+         disclosed in CVE-2016-9147. [RT #43548]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Malformed control messages can trigger assertions in named
-         and rndc. This flaw is disclosed in CVE-2016-1285. [RT
-         #41666]
+         <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
+         records which could trigger an assertion failure when there was
+         a class mismatch. This flaw is disclosed in CVE-2016-9131.
+         [RT #43522]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Certain errors that could be encountered when printing out
-         or logging an OPT record containing a CLIENT-SUBNET option
-         could be mishandled, resulting in an assertion failure.
-         This flaw is disclosed in CVE-2015-8705. [RT #41397]
+         It was possible to trigger assertions when processing
+         responses containing answers of type DNAME. This flaw is
+         disclosed in CVE-2016-8864. [RT #43465]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Specific APL data could trigger an INSIST.  This flaw
-         is disclosed in CVE-2015-8704. [RT #41396]
+         Added the ability to specify the maximum number of records
+         permitted in a zone (<code class="option">max-records #;</code>).
+         This provides a mechanism to block overly large zone
+         transfers, which is a potential risk with slave zones from
+         other parties, as described in CVE-2016-6170.
+         [RT #42143]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Incorrect reference counting could result in an INSIST
-         failure if a socket error occurred while performing a
-         lookup.  This flaw is disclosed in CVE-2015-8461. [RT#40945]
+         It was possible to trigger an assertion when rendering a
+         message using a specially crafted request. This flaw is
+         disclosed in CVE-2016-2776. [RT #43139]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Insufficient testing when parsing a message allowed
-         records with an incorrect class to be be accepted,
-         triggering a REQUIRE failure when those records
-         were subsequently cached.  This flaw is disclosed
-         in CVE-2015-8000. [RT #40987]
+         Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non
+         absolute name could trigger an infinite recursion bug in
+         <span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
+         <span class="command"><strong>lwres</strong></span> configured if, when combined with
+         a search list entry from <code class="filename">resolv.conf</code>,
+         the resulting name is too long.  This flaw is disclosed in
+         CVE-2016-2775. [RT #42694]
        </p>
       </li>
 </ul></div>
-
   </div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_features"></a>New Features</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The following resource record types have been implemented:
-         AVC, CSYNC, NINFO, RKEY, SINK, SMIMEA, TA, TALINK.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added a warning for a common misconfiguration involving forwarded
-         RFC 1918 and IPv6 ULA (Universal Local Address) zones.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Contributed software from Nominum is included in the source at
-         contrib/dnsperf-2.1.0.0-1/. It includes dnsperf for measuring
-         the performance of authoritative DNS servers, resperf for
-         testing the resolution performance of a caching DNS server,
-         resperf-report for generating a resperf report in HTML with
-         gnuplot graphs, and queryparse to extract DNS queries from
-         pcap capture files. This software is not installed by default
-         with BIND.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When loading a signed zone, <span class="command"><strong>named</strong></span> will
-         now check whether an RRSIG's inception time is in the future,
-         and if so, it will regenerate the RRSIG immediately. This helps
-         when a system's clock needs to be reset backwards.
-       </p>
-      </li>
 <li class="listitem">
        <p>
          <span class="command"><strong>named</strong></span> now provides feedback to the
          to yes.
        </p>
       </li>
+<li class="listitem">
+       <p>
+         A new <span class="command"><strong>tcp-only</strong></span> option has been added to
+         <span class="command"><strong>server</strong></span> clauses, to indicate that UDP should
+         not be used when sending queries to a specified IP address or
+         prefix.
+       </p>
+      </li>
 </ul></div>
   </div>
 
       </li>
 <li class="listitem">
        <p>
-         Updated the compiled-in addresses for H.ROOT-SERVERS.NET
-         and L.ROOT-SERVERS.NET.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The default preferred glue is now the address type of the
-         transport the query was received over.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         On machines with 2 or more processors (CPU), the default value
-         for the number of UDP listeners has been changed to the number
-         of detected processors minus one.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Zone transfers now use smaller message sizes to improve
-         message compression. This results in reduced network usage.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         named -V output now also includes operating system details.
+         If an ACL is specified with an address prefix in which the
+         prefix length is longer than the address portion (for example,
+         192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
+         In future releases this will be a fatal configuration error.
+         [RT #43367]
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_port"></a>Porting Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
-       <p>
-         The Microsoft Windows install tool
-         <span class="command"><strong>BINDInstall.exe</strong></span> which requires a
-         non-free version of Visual Studio to be built, now uses two
-         files (lists of flags and files) created by the Configure
-         perl script with all the needed information which were
-         previously compiled in the binary. Read
-         <code class="filename">win32utils/build.txt</code> for more details.
-         [RT #38915]
-       </p>
-      </li></ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
       </li>
 <li class="listitem">
        <p>
-         <span class="command"><strong>rndc flushtree</strong></span> now works even if there wasn't
-         a cached node at the specified name. [RT #41846]
+         Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
+         statement could cause an assertion failure during configuration.
+         [RT #43787]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Don't emit records with zero TTL unless the records were
-         received with a zero TTL. After being returned to waiting
-         clients, the answer will be discarded from the cache. [RT #41687]
+         <span class="command"><strong>rndc addzone</strong></span> could cause a crash
+         when attempting to add a zone with a type other than
+         <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
+         Such zones are now rejected. [RT #43665]
        </p>
       </li>
 <li class="listitem">
        <p>
-         For Windows platforms, the SIT (Source Identity Token) support
-         was restored. (It was mistakenly partially replaced in a
-         previous beta with new 9.11 COOKIE support.) [RT #41905]
+         <span class="command"><strong>named</strong></span> could hang when encountering log
+         file names with large apparent gaps in version number (for
+         example, when files exist called "logfile.0", "logfile.1",
+         and "logfile.1482954169").  This is now handled correctly.
+         [RT #38688]
        </p>
       </li>
 <li class="listitem">
        <p>
-         When deleting records from a zone database, interior nodes
-         could be left empty but not deleted, damaging search
-         performance afterward. [RT #40997] [RT #41941]
+         If a zone was updated while <span class="command"><strong>named</strong></span> was
+         processing a query for nonexistent data, it could return
+         out-of-sync NSEC3 records causing potential DNSSEC validation
+         failure. [RT #43247]
        </p>
       </li>
 <li class="listitem">
        <p>
-         The server could crash due to a use-after-free if a
-         zone transfer timed out. [RT #41297]
+         <span class="command"><strong>named</strong></span> could crash when loading a zone
+         which had RRISG records whose expiry fields were far enough
+         apart to cause an integer overflow when comparing them.
+         [RT #40571]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Authoritative servers that were marked as bogus (e.g. blackholed
-         in configuration or with invalid addresses) were being queried
-         anyway. [RT #41321]
+         The <span class="command"><strong>arpaname</strong></span> and <span class="command"><strong>named-rrchecker</strong></span>
+         commands were not installed into the correct
+         <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code> directory.
+         [RT #42910]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Some of the options for GeoIP ACLs, including "areacode",
-         "metrocode", and "timezone", were incorrectly documented
-         as "area", "metro" and "tz".  Both the long and abbreviated
-         versions are now accepted.
+         When receiving a response from an authoritative server with
+         a TTL value of zero, <span class="command"><strong>named&gt;</strong></span> will now only use
+         that response once, to answer the currently active clients that
+         were waiting for it. Previously, such response could be cached
+         and reused for up to one second. [RT #42142]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Zones configured to use <span class="command"><strong>map</strong></span> format
-         master files can't be used as policy zones because RPZ
-         summary data isn't compiled when such zones are mapped into
-         memory.  This limitation may be fixed in a future release,
-         but in the meantime it has been documented, and attempting
-         to use such zones in <span class="command"><strong>response-policy</strong></span>
-         statements is now a configuration error.  [RT #38321]
+         <span class="command"><strong>named-checkconf</strong></span> now checks the
+         <span class="command"><strong>rate-limit</strong></span> clause for correctness.
+         [RT #42970]
+       </p>
+      </li>
+<li class="listitem">
+       <p>
+         Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
+         that could allow a read past the end of a buffer, crashing
+         <span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
+         this error.
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+       <p>
+         The built-in root hints have been updated to include
+         IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
+         E.ROOT-SERVERS.NET (2001:500:a8::e) and
+         G.ROOT-SERVERS.NET (2001:500:12::d0d).
+       </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
     <p>
       The end of life for BIND 9.10 is yet to be determined but
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 9f60cf798e2d78f26052999eb623ad00bcd0a1cd..55765a09e3e7f2f00a76ce3a059e51319b9e26fd 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 64f5455cee0b6f5382a425bd646d7e8eba2d09b3..cb40321cbd47a263052e6de74dfd3c8e5bed30ce 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index a30bde3d63eb310ca8eebaa70121dab077ee9a31..b77dbe7258fec4c1a8b88e4503c412ab129cd9bb 100644 (file)
@@ -584,6 +584,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index e8d9c8f270ebe51f5d75dd487d99a563e5080e53..cad5863776920ff3a26e0e9a2b517e8fd21bd532 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 17cbb3a98ad441632e58ef5ea4cb5a29f66dd10b..88e3c2d967a758af4694501a6a5ac5107611c7c4 100644 (file)
@@ -41,7 +41,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.10.4</p></div>
+<div><p class="releaseinfo">BIND Version 9.10.5b1</p></div>
 <div><p class="copyright">Copyright Â© 2004-2016 Internet Systems Consortium, Inc. ("ISC")</p></div>
 <div><p class="copyright">Copyright Â© 2000-2003 Internet Software Consortium.</p></div>
 </div>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.4</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.5b1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_port">Porting Changes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
 </dl></dd>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 0f9fb9e85e850fa44e8ab331867f4c4449ad4980..50b1cfe409a1e9875b459329644ce195479bd504 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index ae05faf293bb721e9e045237ea5041b1a7be9bb3..d142f4e40946d05c3f0c28344d590777adc8ea3a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 3e8373ef4b444a52e410b085fdf3507118f0fc33..b1ec8a2d6fd59f02c96a16e7468428ae58d74a1d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 4e00189b9d88776d46a3e9da3e5f1d90f00626f7..60a6b0b16a21da655c8193e96500adf8f3251260 100644 (file)
@@ -1029,6 +1029,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 1ae925acc7bb45ece44e7894b00ca559a1491582..884ce67ee7c71311e93433281a1888a609683592 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index d0356be7c0a80dfcbbe84b2bb880daa8c5bda169..6618485e3c313a9c5730481775b5e7bc483d911c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 52a75fd4fe257a5167f20f44b71a55d3a0548e56..935b1491305603f024c784e0a88885654913998d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 1ccebdd479e1ae7a51615c49502f622041241145..14012f65f7017bcffe7e838b83e3512e217928f0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index c4bec39748a0f427165b728aa6842432fb3783de..fe2727fa5fa4230cc30d5563802d51fb1122cab7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 162ac4d284ec7a51e8e520b32c50d7d4fc4372a8..f9bcef9092d56fe349e2a10c49b397dcdf85b30a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 4d8edd8291514f85d7ae041fd05b10c93b47e55a..598016986d60f6bb29924e53c466c16c6115989d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 650a089736d141d52b27bd63594b68a0f81269ac..5979a94033600af9dbd85ea42960d8d7ed911d6f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index cd7f1dfa1758f6270204494f3391c03e7dd35587..cc204fd444a328e7a8444bca378727f7ef19dbd4 100644 (file)
@@ -711,6 +711,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 28c684e79f03557dbdee13012c80d7a8204f610b..490d804df1a684f2065b4cf7d0df5dc352c3c226 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index e38be520f527bb2909ff25975d2aa1ee9ca3cf30..d29db159f05eaefbfcbae6ad67ab825a47f35728 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 547f77739e5e29c5d3a04deab1467d20c7329cac..2c88dae8713c998896a01bb0159d7a982a3b0737 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 52389d2d2ba877b6f5a384200953bd147e6ce99b..3601899751785146f2d6368dcb3ba9e5b78391e0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 83a06b6e2067b4e959db9ac90fe213f7f29787a7..c1fe8976845b333e8571f6ec86224806a724d30d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 862d87e6fd7e0cc767c920fb7cbfe43a1e46f017..11a806eedda502629d326708a84f6169f1d19b85 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 69f3641d1e44633f9d634b5e216136713bcb7f66..19d107018eb183af6c7ce63d95fb00559baa8ad2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index df9e6f89458da58ae901d654bb13f2c97ff6cff3..09345ab93eab049168ec1740a24fb4b3cc2132ae 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 79fb3ebcea8b8033642f9b397064014ecb8f6f4c..4d212255661556f46ec10ef2dbfb7f3cb0a98653 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 548f71f10bb2172c603726ca6538528aaf3388de..59021a7e1fc63a1306d7401a03f7434d9bd89dd6 100644 (file)
@@ -736,6 +736,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index bf160168522e385dffd8c42fe153309691e5d216..9fda18a74cc2c88d5df85c61f424b9eea9775206 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index dad3d8d220125ba184bcb3123d96cb4655efb850..4f37c7e5599dfeb09dccdd94d627b694e8b8c2b7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index d97396e72717c9d67940dfde60ecde7114075b98..908db8376ddb0c15a4c48f0f7c13ae79e4a7a69d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 0426cf0349deb4f732a242597d2abcc150541440..4d64761372d187fb375932a09505398430529cb5 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 6bfdc87c57cfc2b0053643938ef8756f247fc833..f961fe8e02095b5feb3048e33cfc9989009b4d14 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index 5b748942fd1fc9755dd8d61cdc30b0b140c71e39..668a56b91872d2321250e83f52e4691348db9a08 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.4</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5b1</p>
 </body>
 </html>
index c781b9ac40e5e633c7e2bccc4130b4419c01be29..653292baf6127dd12483ee13ce90ab9f00ffdd8c 100644 (file)
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.10.4</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.10.5b1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes significant changes since the last
-      production release of BIND on the corresponding major release
-      branch.
-      Please see the CHANGES file for a further list of bug fixes and
-      other changes.
+      This document summarizes changes since the last production
+      release on the BIND 9.10 branch.
+      Please see the <code class="filename">CHANGES</code> file for a further
+      list of bug fixes and other changes.
     </p>
   </div>
 
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
        <p>
-         Added the ability to specify the maximum number of records
-         permitted in a zone (max-records #;).  This provides a mechanism
-         to block overly large zone transfers, which is a potential risk
-         with slave zones from other parties, as described in CVE-2016-6170.
-         [RT #42143]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger a assertion when rendering a
-         message using a specially crafted request. This flaw is
-         disclosed in CVE-2016-2776. [RT #43139]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-        getrrsetbyname with a non absolute name could trigger an
-        infinite recursion bug in lwresd and named with lwres
-        configured if when combined with a search list entry the
-        resulting name is too long.  This flaw is disclosed in
-        CVE-2016-2775. [RT #42694]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Duplicate EDNS COOKIE options in a response could trigger
-         an assertion failure. This flaw is disclosed in CVE-2016-2088.
-         [RT #41809]
+         <span class="command"><strong>named</strong></span> could mishandle authority sections
+         with missing RRSIGs, triggering an assertion failure. This
+         flaw is disclosed in CVE-2016-9444. [RT #43632]
        </p>
       </li>
 <li class="listitem">
        <p>
-         The resolver could abort with an assertion failure due to
-         improper DNAME handling when parsing fetch reply
-         messages. This flaw is disclosed in CVE-2016-1286. [RT #41753]
+         <span class="command"><strong>named</strong></span> mishandled some responses where
+         covering RRSIG records were returned without the requested
+         data, resulting in an assertion failure. This flaw is
+         disclosed in CVE-2016-9147. [RT #43548]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Malformed control messages can trigger assertions in named
-         and rndc. This flaw is disclosed in CVE-2016-1285. [RT
-         #41666]
+         <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
+         records which could trigger an assertion failure when there was
+         a class mismatch. This flaw is disclosed in CVE-2016-9131.
+         [RT #43522]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Certain errors that could be encountered when printing out
-         or logging an OPT record containing a CLIENT-SUBNET option
-         could be mishandled, resulting in an assertion failure.
-         This flaw is disclosed in CVE-2015-8705. [RT #41397]
+         It was possible to trigger assertions when processing
+         responses containing answers of type DNAME. This flaw is
+         disclosed in CVE-2016-8864. [RT #43465]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Specific APL data could trigger an INSIST.  This flaw
-         is disclosed in CVE-2015-8704. [RT #41396]
+         Added the ability to specify the maximum number of records
+         permitted in a zone (<code class="option">max-records #;</code>).
+         This provides a mechanism to block overly large zone
+         transfers, which is a potential risk with slave zones from
+         other parties, as described in CVE-2016-6170.
+         [RT #42143]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Incorrect reference counting could result in an INSIST
-         failure if a socket error occurred while performing a
-         lookup.  This flaw is disclosed in CVE-2015-8461. [RT#40945]
+         It was possible to trigger an assertion when rendering a
+         message using a specially crafted request. This flaw is
+         disclosed in CVE-2016-2776. [RT #43139]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Insufficient testing when parsing a message allowed
-         records with an incorrect class to be be accepted,
-         triggering a REQUIRE failure when those records
-         were subsequently cached.  This flaw is disclosed
-         in CVE-2015-8000. [RT #40987]
+         Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non
+         absolute name could trigger an infinite recursion bug in
+         <span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
+         <span class="command"><strong>lwres</strong></span> configured if, when combined with
+         a search list entry from <code class="filename">resolv.conf</code>,
+         the resulting name is too long.  This flaw is disclosed in
+         CVE-2016-2775. [RT #42694]
        </p>
       </li>
 </ul></div>
-
   </div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_features"></a>New Features</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The following resource record types have been implemented:
-         AVC, CSYNC, NINFO, RKEY, SINK, SMIMEA, TA, TALINK.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added a warning for a common misconfiguration involving forwarded
-         RFC 1918 and IPv6 ULA (Universal Local Address) zones.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Contributed software from Nominum is included in the source at
-         contrib/dnsperf-2.1.0.0-1/. It includes dnsperf for measuring
-         the performance of authoritative DNS servers, resperf for
-         testing the resolution performance of a caching DNS server,
-         resperf-report for generating a resperf report in HTML with
-         gnuplot graphs, and queryparse to extract DNS queries from
-         pcap capture files. This software is not installed by default
-         with BIND.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When loading a signed zone, <span class="command"><strong>named</strong></span> will
-         now check whether an RRSIG's inception time is in the future,
-         and if so, it will regenerate the RRSIG immediately. This helps
-         when a system's clock needs to be reset backwards.
-       </p>
-      </li>
 <li class="listitem">
        <p>
          <span class="command"><strong>named</strong></span> now provides feedback to the
          to yes.
        </p>
       </li>
+<li class="listitem">
+       <p>
+         A new <span class="command"><strong>tcp-only</strong></span> option has been added to
+         <span class="command"><strong>server</strong></span> clauses, to indicate that UDP should
+         not be used when sending queries to a specified IP address or
+         prefix.
+       </p>
+      </li>
 </ul></div>
   </div>
 
       </li>
 <li class="listitem">
        <p>
-         Updated the compiled-in addresses for H.ROOT-SERVERS.NET
-         and L.ROOT-SERVERS.NET.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The default preferred glue is now the address type of the
-         transport the query was received over.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         On machines with 2 or more processors (CPU), the default value
-         for the number of UDP listeners has been changed to the number
-         of detected processors minus one.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Zone transfers now use smaller message sizes to improve
-         message compression. This results in reduced network usage.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         named -V output now also includes operating system details.
+         If an ACL is specified with an address prefix in which the
+         prefix length is longer than the address portion (for example,
+         192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
+         In future releases this will be a fatal configuration error.
+         [RT #43367]
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_port"></a>Porting Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
-       <p>
-         The Microsoft Windows install tool
-         <span class="command"><strong>BINDInstall.exe</strong></span> which requires a
-         non-free version of Visual Studio to be built, now uses two
-         files (lists of flags and files) created by the Configure
-         perl script with all the needed information which were
-         previously compiled in the binary. Read
-         <code class="filename">win32utils/build.txt</code> for more details.
-         [RT #38915]
-       </p>
-      </li></ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
       </li>
 <li class="listitem">
        <p>
-         <span class="command"><strong>rndc flushtree</strong></span> now works even if there wasn't
-         a cached node at the specified name. [RT #41846]
+         Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
+         statement could cause an assertion failure during configuration.
+         [RT #43787]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Don't emit records with zero TTL unless the records were
-         received with a zero TTL. After being returned to waiting
-         clients, the answer will be discarded from the cache. [RT #41687]
+         <span class="command"><strong>rndc addzone</strong></span> could cause a crash
+         when attempting to add a zone with a type other than
+         <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
+         Such zones are now rejected. [RT #43665]
        </p>
       </li>
 <li class="listitem">
        <p>
-         For Windows platforms, the SIT (Source Identity Token) support
-         was restored. (It was mistakenly partially replaced in a
-         previous beta with new 9.11 COOKIE support.) [RT #41905]
+         <span class="command"><strong>named</strong></span> could hang when encountering log
+         file names with large apparent gaps in version number (for
+         example, when files exist called "logfile.0", "logfile.1",
+         and "logfile.1482954169").  This is now handled correctly.
+         [RT #38688]
        </p>
       </li>
 <li class="listitem">
        <p>
-         When deleting records from a zone database, interior nodes
-         could be left empty but not deleted, damaging search
-         performance afterward. [RT #40997] [RT #41941]
+         If a zone was updated while <span class="command"><strong>named</strong></span> was
+         processing a query for nonexistent data, it could return
+         out-of-sync NSEC3 records causing potential DNSSEC validation
+         failure. [RT #43247]
        </p>
       </li>
 <li class="listitem">
        <p>
-         The server could crash due to a use-after-free if a
-         zone transfer timed out. [RT #41297]
+         <span class="command"><strong>named</strong></span> could crash when loading a zone
+         which had RRISG records whose expiry fields were far enough
+         apart to cause an integer overflow when comparing them.
+         [RT #40571]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Authoritative servers that were marked as bogus (e.g. blackholed
-         in configuration or with invalid addresses) were being queried
-         anyway. [RT #41321]
+         The <span class="command"><strong>arpaname</strong></span> and <span class="command"><strong>named-rrchecker</strong></span>
+         commands were not installed into the correct
+         <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code> directory.
+         [RT #42910]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Some of the options for GeoIP ACLs, including "areacode",
-         "metrocode", and "timezone", were incorrectly documented
-         as "area", "metro" and "tz".  Both the long and abbreviated
-         versions are now accepted.
+         When receiving a response from an authoritative server with
+         a TTL value of zero, <span class="command"><strong>named&gt;</strong></span> will now only use
+         that response once, to answer the currently active clients that
+         were waiting for it. Previously, such response could be cached
+         and reused for up to one second. [RT #42142]
        </p>
       </li>
 <li class="listitem">
        <p>
-         Zones configured to use <span class="command"><strong>map</strong></span> format
-         master files can't be used as policy zones because RPZ
-         summary data isn't compiled when such zones are mapped into
-         memory.  This limitation may be fixed in a future release,
-         but in the meantime it has been documented, and attempting
-         to use such zones in <span class="command"><strong>response-policy</strong></span>
-         statements is now a configuration error.  [RT #38321]
+         <span class="command"><strong>named-checkconf</strong></span> now checks the
+         <span class="command"><strong>rate-limit</strong></span> clause for correctness.
+         [RT #42970]
+       </p>
+      </li>
+<li class="listitem">
+       <p>
+         Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
+         that could allow a read past the end of a buffer, crashing
+         <span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
+         this error.
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+       <p>
+         The built-in root hints have been updated to include
+         IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
+         E.ROOT-SERVERS.NET (2001:500:a8::e) and
+         G.ROOT-SERVERS.NET (2001:500:12::d0d).
+       </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
     <p>
       The end of life for BIND 9.10 is yet to be determined but