]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
prep 9.11.30
authorTinderbox User <tbox@isc.org>
Mon, 12 Apr 2021 13:44:15 +0000 (13:44 +0000)
committerMichał Kępień <michal@isc.org>
Thu, 29 Apr 2021 09:56:03 +0000 (11:56 +0200)
62 files changed:
CHANGES
README
README.md
configure
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt
lib/dns/api
version

diff --git a/CHANGES b/CHANGES
index 36db5301370070938255f2e76fa966fa57cd3288..cef13738f44c760bf1fcee8154e4bd4eb223169c 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -5,6 +5,8 @@
                        configuration included the "tkey-gssapi-credential"
                        option. This has been fixed. [GL #2634]
 
+       --- 9.11.30 released ---
+
 5617.  [security]      A specially crafted GSS-TSIG query could cause a buffer
                        overflow in the ISC implementation of SPNEGO.
                        (CVE-2021-25216) [GL #2604]
diff --git a/README b/README
index bd12f96cec73d2e702fd424aa916497e984ae1f2..bf2eef7817b6498d8b422829b5193e3546c5bb2c 100644 (file)
--- a/README
+++ b/README
@@ -377,6 +377,12 @@ BIND 9.11.29
 
 BIND 9.11.29 is a maintenance release.
 
+BIND 9.11.30
+
+BIND 9.11.30 is a maintenance release, and also addresses the security
+vulnerabilities disclosed in CVE-2021-25214, CVE-2021-25215, and
+CVE-2021-25216.
+
 Building BIND
 
 Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
index 6ecb9b3b73d6b01cd51a85017cc51a4a685fc36c..201124153e08547523cb34f61bf3d43ffa7462d8 100644 (file)
--- a/README.md
+++ b/README.md
@@ -394,6 +394,12 @@ vulnerability disclosed in CVE-2020-8625.
 
 BIND 9.11.29 is a maintenance release.
 
+#### BIND 9.11.30
+
+BIND 9.11.30 is a maintenance release, and also addresses the security
+vulnerabilities disclosed in CVE-2021-25214, CVE-2021-25215, and
+CVE-2021-25216.
+
 ### <a name="build"/> Building BIND
 
 Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
index ce5a1dca9d950934585e467951be898b83e194cb..5e68976c6f7dab24ab77d18476d1e28d7fd2fe48 100755 (executable)
--- a/configure
+++ b/configure
@@ -978,7 +978,6 @@ infodir
 docdir
 oldincludedir
 includedir
-runstatedir
 localstatedir
 sharedstatedir
 sysconfdir
@@ -1152,7 +1151,6 @@ datadir='${datarootdir}'
 sysconfdir='${prefix}/etc'
 sharedstatedir='${prefix}/com'
 localstatedir='${prefix}/var'
-runstatedir='${localstatedir}/run'
 includedir='${prefix}/include'
 oldincludedir='/usr/include'
 docdir='${datarootdir}/doc/${PACKAGE_TARNAME}'
@@ -1405,15 +1403,6 @@ do
   | -silent | --silent | --silen | --sile | --sil)
     silent=yes ;;
 
-  -runstatedir | --runstatedir | --runstatedi | --runstated \
-  | --runstate | --runstat | --runsta | --runst | --runs \
-  | --run | --ru | --r)
-    ac_prev=runstatedir ;;
-  -runstatedir=* | --runstatedir=* | --runstatedi=* | --runstated=* \
-  | --runstate=* | --runstat=* | --runsta=* | --runst=* | --runs=* \
-  | --run=* | --ru=* | --r=*)
-    runstatedir=$ac_optarg ;;
-
   -sbindir | --sbindir | --sbindi | --sbind | --sbin | --sbi | --sb)
     ac_prev=sbindir ;;
   -sbindir=* | --sbindir=* | --sbindi=* | --sbind=* | --sbin=* \
@@ -1551,7 +1540,7 @@ fi
 for ac_var in  exec_prefix prefix bindir sbindir libexecdir datarootdir \
                datadir sysconfdir sharedstatedir localstatedir includedir \
                oldincludedir docdir infodir htmldir dvidir pdfdir psdir \
-               libdir localedir mandir runstatedir
+               libdir localedir mandir
 do
   eval ac_val=\$$ac_var
   # Remove trailing slashes.
@@ -1704,7 +1693,6 @@ Fine tuning of the installation directories:
   --sysconfdir=DIR        read-only single-machine data [PREFIX/etc]
   --sharedstatedir=DIR    modifiable architecture-independent data [PREFIX/com]
   --localstatedir=DIR     modifiable single-machine data [PREFIX/var]
-  --runstatedir=DIR       modifiable per-process data [LOCALSTATEDIR/run]
   --libdir=DIR            object code libraries [EPREFIX/lib]
   --includedir=DIR        C header files [PREFIX/include]
   --oldincludedir=DIR     C header files for non-gcc [/usr/include]
index 297269af6f663ca81d44bc8f19d1923ec5aedd4a..baf9e036bd09b1cc6220a0e3033db7fd285fc373 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index af2cce96e06ca54e0d3aff731481644ea31b29c4..674e15c4081ae9198be1ab788384695fcecd294c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 2d83e5515a68f17cf989cfd217d006a6462eab2f..94eb812f52337706419b2de12915a6ce6a4223b0 100644 (file)
@@ -654,6 +654,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index d72442c6a23f38eeb7355dcf550a0e493ad7da33..9016b8d5829055f52beedf8f5150d5bfc5c840d6 100644 (file)
@@ -2664,6 +2664,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 5d9930e588cb279a7c57ca32d5d2045d73a26b38..efb6fcf46ac1a5dfc19185a44e4d0b719294253d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 71159d1733eb294be2394c4564981dc6c6dc9ffd..beeb7ea810249b6791287fca233fd23bfeb9697d 100644 (file)
@@ -12842,6 +12842,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 2d74cbba3576c6ae012a0aec6a66f945945b3f72..861895d2057d8f079ee8ba1338534408f7eb4675 100644 (file)
@@ -384,6 +384,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index be4f81d5ff6470f603059b56d71e27eb8bdc7f33..2f4ae0f4b2a158902e7b75432684e38e7e78a62b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 5d2b86430355f36b4080c5ff921e9aff24f398f1..c3be5e80ed894a0c741e248e08003a2fcab9ee11 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.29</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.30</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.30">Notes for BIND 9.11.30</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.29">Notes for BIND 9.11.29</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.28">Notes for BIND 9.11.28</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.27">Notes for BIND 9.11.27</a></span></dt>
@@ -78,7 +79,7 @@
 </div>
 <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.29</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.30</h2></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
 </div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.11.30"></a>Notes for BIND 9.11.30</h3></div></div></div>
+<div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.11.30-security"></a>Security Fixes</h4></div></div></div>
+<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+<p>
+          A malformed incoming IXFR transfer could trigger an assertion failure
+          in <span class="command"><strong>named</strong></span>, causing it to quit abnormally.
+          (CVE-2021-25214)
+        </p>
+<p>
+          ISC would like to thank Greg Kuechle of SaskTel for bringing this
+          vulnerability to our attention. [GL #2467]
+        </p>
+</li>
+<li class="listitem">
+<p>
+          <span class="command"><strong>named</strong></span> crashed when a DNAME record placed in the
+          ANSWER section during DNAME chasing turned out to be the final answer
+          to a client query. (CVE-2021-25215)
+        </p>
+<p>
+          ISC would like to thank <a class="link" href="https://github.com/sivakesava1" target="_top">Siva Kakarla</a> for
+          bringing this vulnerability to our attention. [GL #2540]
+        </p>
+</li>
+<li class="listitem">
+<p>
+          When a server's configuration set the
+          <span class="command"><strong>tkey-gssapi-keytab</strong></span> or
+          <span class="command"><strong>tkey-gssapi-credential</strong></span> option, a specially crafted
+          GSS-TSIG query could cause a buffer overflow in the ISC implementation
+          of SPNEGO (a protocol enabling negotiation of the security mechanism
+          used for GSSAPI authentication). This flaw could be exploited to crash
+          <span class="command"><strong>named</strong></span> binaries compiled for 64-bit platforms, and
+          could enable remote code execution when <span class="command"><strong>named</strong></span> was
+          compiled for 32-bit platforms. (CVE-2021-25216)
+        </p>
+<p>
+          This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro
+          Zero Day Initiative. [GL #2604]
+        </p>
+</li>
+</ul></div>
+</div>
+<div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.11.30-changes"></a>Feature Changes</h4></div></div></div>
+<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem"><p>
+          The ISC implementation of SPNEGO was removed from BIND 9 source code.
+          Instead, BIND 9 now always uses the SPNEGO implementation provided by
+          the system GSSAPI library when it is built with GSSAPI support. All
+          major contemporary Kerberos/GSSAPI libraries contain an implementation
+          of the SPNEGO mechanism. [GL #2607]
+        </p></li></ul></div>
+</div>
+</div>
+<div class="section">
+<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes-9.11.29"></a>Notes for BIND 9.11.29</h3></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h4 class="title">
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 1a83baabc7acf55a828285dfa125789ab1aa920b..fa6e8b86a34e23c86b7181df9b9b9287b81fd6ec 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 297ffeee1b7dd9740bb23e8d4cfe29fa6e48362c..605dc65bd70820976f4f952ec0eaf78849cb0a6b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 0a3d7347d096fd03ac0e6f41800f33de14183bde..8945031a4967d0d9601b43f975939323433debad 100644 (file)
@@ -473,6 +473,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index c3079b345d292ba5c508e1869944d9e7637ac3f6..46d93717a6df7a45cef16fb147ccbc1cae33bba3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index bf2f7992f872a9528c12eabfc9c94bc93ed6562b..c17434a0b1b10a79c79fb6eeb74c3bca0c277552 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.11.29</p></div>
+<div><p class="releaseinfo">BIND Version 9.11.30</p></div>
 <div><p class="copyright">Copyright © 2000-2021 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.29</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.30</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.30">Notes for BIND 9.11.30</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.29">Notes for BIND 9.11.29</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.28">Notes for BIND 9.11.28</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.27">Notes for BIND 9.11.27</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index b70e1aed1ab5167f6c9759b4d5963054b3b617b6..a46b1d63f07f889506f6f4375c57ec19a52e1931 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index f1b76abd413bbf89b2a109c0aa7b78c2ae0a7346..782b98c15a703253bb256d4987f739836e6142b0 100644 (file)
@@ -72,6 +72,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index a6ca0f2bf69b4f2c1c02b7cd17ae04fda9e64240..7e7bbe1199c9a6eec7310f474f272661a67d4390 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 17f9b4b34164e7970f4466b9c828609ea5952779..ac575f21095237655ce200fb33feaf67a2302b03 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 24118057bac4eca62d699ebefcac215c805a29a1..2207c2e1c09c489dc1495878e7b177527f32e89e 100644 (file)
@@ -919,6 +919,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index ef802f988ded3ccc0e85950207bda2f5bce4cefc..a3b9b90e920829b385124058706270bbc2141e0a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index d162c59c51e93d0facd5375767d09d6b2f8e66d3..c29b101fc0a77c0f8e9fa8ae1a1b4970a1f6740d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 3f494aafcdc2ab852c9f85567cf2dceb1b4a1b0b..503d6673294cfeec3364918a92604300d50dce17 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 79d8e46fa3a254bedeccc30b53896d75bd895f1c..e10fda6c592bb68f53347a2fef557bbce06ca377 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 1e0e1fff2573bf92bdaf208243712e546572002c..2cac5ecf9f4ad6d039849278a622953a985f9640 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 2d0c44b9e6a7fbd1dcd1388d9aa197f647ee8c74..db9703745d43ddc36d48765c26d8db758eac59de 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index bfbd8c5d985824f88f1d84093b208c128a53c78b..49f83657670b057c6b063a0e844a08fb6cf2d802 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index ad045a05f9132590abe6ec5baca7c6e042d7ad35..f71342439840ebb3e39237c67b7bcb4dec3d5b00 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index e712d08de4b70650cbceb10eee248173fc114005..7777c518a9a07a5da80225769ec42d763dae8ca9 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index da683e4b3a52d5a3b4ae1732d9c4b902e6cfeadd..fc6d5a6344955f8efb7ed7cb3143b86eeaa00575 100644 (file)
@@ -559,6 +559,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 8e29d2639c29a424b948d327222df567d1ef2604..8a17131a214a16abfb7ff72639a1790288f09e9a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index b66a96ad2716bba7c5c5af83552dc61f0606f9a3..6e473e206c6d4fecd400f49f95e1338447c0d963 100644 (file)
@@ -99,6 +99,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 820063c3b20d9122e027cfe3a5e2dd6a35c5e139..956fe087e3818e994e6d8a8046f15f29c99c3a2d 100644 (file)
@@ -93,6 +93,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 003a51bbda833c9408b8da375897d4f202c206eb..38bd135f79d1821319de5c4271d074da2e3f9892 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 6dfdf67314fa131fe0bc8ff50f9b4854de731e7d..72a132e0201cbf9431025c5159a5478cfc153e2a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 6a6bd34e9307baf6c21bec50ae5bf66bff7d5ae1..722c4471d1289f14b301214954911450e019ec55 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 1e8eb961319c84257161a3618d372a6dc982aedf..95c74f7d282ca7cd022b55af7608c18b5a1029ba 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index bfe101c62e106c71255ed4b7fecc13930f96984e..9f4ae310401120d6be2520338dede0e723f23418 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 6481c190afd9f4d375c0d549415c9a02046d1cf3..0a45ad9ccb9fcadb9b95ac102767a49abfe9da64 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 02c19cc4521a4318885453660a62caeec36e6a63..99c3a03f51f694fe2807ff75a34992037de72707 100644 (file)
@@ -94,6 +94,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 5be2d85b0137094cf17ba9339cf51aa8a6c8aaab..7912aefb9c1537da889736fb8c657044eeb7c973 100644 (file)
@@ -95,6 +95,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index e94f738ffadae5e591b721ba9ce9784af45adc10..580109688f4f8c88eafd7dee28e903f0b6fa2320 100644 (file)
@@ -96,6 +96,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 4de64b3bf08b73d6af6a4aa6633173f73eea0418..e376835854d3fc73766e83f33852df9b9bb439bc 100644 (file)
@@ -974,6 +974,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index ac93282c0ba038d24cd5728797375198737e45a9..deeb49a1127cce5d68a530c283d70235720bd6ef 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 72179c6393f9f15c0da05d2c43f7540c97b06b80..0960006b2d909002fd4457d3d358f17b4cc53b6d 100644 (file)
@@ -98,6 +98,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 77b4e81428b275a03d90009646ce6cf5332cfa87..8a09cf4a47e897ac76cbc3cc94b3d671ae8e9335 100644 (file)
@@ -362,6 +362,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 7c52e46e3c589d3b9180517e1532ce13bc72a092..b6da68d703975c81efbb51e450abd7c1d0c8012b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 11a215ce8d43144e0286b252cc0632eef20a0bfe..53b8c7cfa7684d72f3d751718bf65977c23d3369 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 91cd25b019b6c31b8834350b836217d3caf2b9cc..38a6c4c1aa4a110adcfe6d015c4e18815c4f76d5 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index f204f9b62f12dfe848a0fd46658ba6e90f2c3705..d9f6c90abb2a2cd7330667e65e31b701aae14136 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 83bbdd81f3ad21680c0f54da110beeda8765913b..789b5a9c2aaca1c8ce3f6a7c0651d56615ed10fe 100644 (file)
@@ -91,6 +91,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 28d28ff4eea6ef39b8c2df271a2029a7834df19d..e62c54dc24d218ee872ce7e0004717bd62e565de 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index e2f7d7f95c51d44f60d8aee0bbf20556640d8373..c2427ef5be50161c2bffa790d2020a4c71235369 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index 899ac2dd57016cc6d07710dac45b720dbc7a6a3b..776ae85ea678a33c79f919a7a3dcdb676c2692ee 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.29 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.30 (Extended Support Version)</p>
 </body>
 </html>
index e2f0a54f5d606873159dff6827f6309dc0c5b02c..bc1dcbe782505b07ddcbc0299caa9322d7af2e5e 100644 (file)
@@ -13,7 +13,7 @@
 </head>
 <body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="article"><div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.11.29</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.11.30</h2></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
 </div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.11.30"></a>Notes for BIND 9.11.30</h3></div></div></div>
+<div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.11.30-security"></a>Security Fixes</h4></div></div></div>
+<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+<p>
+          A malformed incoming IXFR transfer could trigger an assertion failure
+          in <span class="command"><strong>named</strong></span>, causing it to quit abnormally.
+          (CVE-2021-25214)
+        </p>
+<p>
+          ISC would like to thank Greg Kuechle of SaskTel for bringing this
+          vulnerability to our attention. [GL #2467]
+        </p>
+</li>
+<li class="listitem">
+<p>
+          <span class="command"><strong>named</strong></span> crashed when a DNAME record placed in the
+          ANSWER section during DNAME chasing turned out to be the final answer
+          to a client query. (CVE-2021-25215)
+        </p>
+<p>
+          ISC would like to thank <a class="link" href="https://github.com/sivakesava1" target="_top">Siva Kakarla</a> for
+          bringing this vulnerability to our attention. [GL #2540]
+        </p>
+</li>
+<li class="listitem">
+<p>
+          When a server's configuration set the
+          <span class="command"><strong>tkey-gssapi-keytab</strong></span> or
+          <span class="command"><strong>tkey-gssapi-credential</strong></span> option, a specially crafted
+          GSS-TSIG query could cause a buffer overflow in the ISC implementation
+          of SPNEGO (a protocol enabling negotiation of the security mechanism
+          used for GSSAPI authentication). This flaw could be exploited to crash
+          <span class="command"><strong>named</strong></span> binaries compiled for 64-bit platforms, and
+          could enable remote code execution when <span class="command"><strong>named</strong></span> was
+          compiled for 32-bit platforms. (CVE-2021-25216)
+        </p>
+<p>
+          This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro
+          Zero Day Initiative. [GL #2604]
+        </p>
+</li>
+</ul></div>
+</div>
+<div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.11.30-changes"></a>Feature Changes</h4></div></div></div>
+<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem"><p>
+          The ISC implementation of SPNEGO was removed from BIND 9 source code.
+          Instead, BIND 9 now always uses the SPNEGO implementation provided by
+          the system GSSAPI library when it is built with GSSAPI support. All
+          major contemporary Kerberos/GSSAPI libraries contain an implementation
+          of the SPNEGO mechanism. [GL #2607]
+        </p></li></ul></div>
+</div>
+</div>
+<div class="section">
+<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes-9.11.29"></a>Notes for BIND 9.11.29</h3></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h4 class="title">
index 77f16d327a4ef9a57962a8424a65d864056adf7b..a6f549f499dc32f4ddaf883364bcc8b540b16ce6 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index c67f18a17df8e2a560efa389b5ec611b1b2f68cf..c75771b09dd776596604cc020ba8dc199e1b3b4d 100644 (file)
@@ -1,4 +1,4 @@
-Release Notes for BIND Version 9.11.29
+Release Notes for BIND Version 9.11.30
 
 Introduction
 
@@ -36,6 +36,43 @@ Those unsure whether or not the license change affects their use of BIND,
 or who wish to discuss how to comply with the license may contact ISC at
 https://www.isc.org/mission/contact/.
 
+Notes for BIND 9.11.30
+
+Security Fixes
+
+  • A malformed incoming IXFR transfer could trigger an assertion failure
+    in named, causing it to quit abnormally. (CVE-2021-25214)
+
+    ISC would like to thank Greg Kuechle of SaskTel for bringing this
+    vulnerability to our attention. [GL #2467]
+
+  • named crashed when a DNAME record placed in the ANSWER section during
+    DNAME chasing turned out to be the final answer to a client query.
+    (CVE-2021-25215)
+
+    ISC would like to thank Siva Kakarla for bringing this vulnerability
+    to our attention. [GL #2540]
+
+  • When a server's configuration set the tkey-gssapi-keytab or
+    tkey-gssapi-credential option, a specially crafted GSS-TSIG query
+    could cause a buffer overflow in the ISC implementation of SPNEGO (a
+    protocol enabling negotiation of the security mechanism used for
+    GSSAPI authentication). This flaw could be exploited to crash named
+    binaries compiled for 64-bit platforms, and could enable remote code
+    execution when named was compiled for 32-bit platforms.
+    (CVE-2021-25216)
+
+    This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro
+    Zero Day Initiative. [GL #2604]
+
+Feature Changes
+
+  • The ISC implementation of SPNEGO was removed from BIND 9 source code.
+    Instead, BIND 9 now always uses the SPNEGO implementation provided by
+    the system GSSAPI library when it is built with GSSAPI support. All
+    major contemporary Kerberos/GSSAPI libraries contain an implementation
+    of the SPNEGO mechanism. [GL #2607]
+
 Notes for BIND 9.11.29
 
 Bug Fixes
index 9112a5f2187d9577b9d0e537e918d6fb700ff3c9..0418fc842fd009becf13249c71a4daefa3390e35 100644 (file)
@@ -8,6 +8,6 @@
 # 9.10-sub: 180-189
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
-LIBINTERFACE = 1113
-LIBREVISION = 2
+LIBINTERFACE = 1114
+LIBREVISION = 0
 LIBAGE = 0
diff --git a/version b/version
index a4f4f7a2cae6b0e4ff985be4f003dc187e2aaa4f..9ec5dc889977c3cfdb0f3c205fe670256d366b6e 100644 (file)
--- a/version
+++ b/version
@@ -5,7 +5,7 @@ PRODUCT=BIND
 DESCRIPTION="(Extended Support Version)"
 MAJORVER=9
 MINORVER=11
-PATCHVER=29
+PATCHVER=30
 RELEASETYPE=
 RELEASEVER=
 EXTENSIONS=