| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: bind-dnssec-utils | Distribution: CentOS |
| Version: 9.18.33 | Vendor: CentOS |
| Release: 28.el10 | Build date: Mon Sep 7 16:37:45 2026 |
| Group: Unspecified | Build host: ppc64le-09.stream.rdu2.redhat.com |
| Size: 718943 | Source RPM: bind-9.18.33-28.el10.src.rpm |
| Packager: builder@centos.org | |
| Url: https://www.isc.org/downloads/bind/ | |
| Summary: DNSSEC keys and zones management utilities | |
bind-dnssec-utils contains a collection of utilities for editing DNSSEC keys and BIND zone files. These tools provide generation, revocation and verification of keys and DNSSEC signatures in zone files. You should install bind-dnssec-utils if you need to sign a DNS zone or maintain keys for it.
MPL-2.0 AND ISC AND MIT AND BSD-3-Clause AND BSD-2-Clause
* Mon Sep 07 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-28
- Rebuild to become part of regular release
* Wed Sep 02 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-27
- Add new root key 38696 into package files too (RHEL-77714)
* Wed Aug 19 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-26
- Avoid unbounded recursion loop (CVE-2026-5950)
- Limit overlapping addresses resolver usage (CVE-2026-3592)
* Mon Jul 27 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.33-25
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)
* Fri Jul 24 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.33-24
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.33-23
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.33-22
- Fix RRSIG label count validation for wildcard cache poisoning
(CVE-2026-11721)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.33-21
- Fix RPZ name-too-long wildcard expansion (CVE-2026-11331)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.33-20
- Fix assertion failure on malformed NSEC/NSEC3 responses
(CVE-2026-13204)
* Mon May 25 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-19
- Fix GSS-API resource leak (CVE-2026-3039)
- Invalid handling of CLASS != IN (CVE-2026-5946)
* Fri Mar 27 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-18
- Prevent Denial of Service via maliciously crafted DNSSEC-validated zone
(CVE-2026-1519)
* Thu Feb 26 2026 Fedor Vorobev <fvorobev@redhat.com> - 32:9.18.33-17
- Backport fixes for stale CNAME chains. (RHEL-142289)
* Wed Jan 28 2026 Fedor Vorobev <fvorobev@redhat.com> - 32:9.18.33-16
- Backport fix for manual DNSSEC key rolllovers. (RHEL-144421)
* Wed Jan 28 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-15
- Add forgotten _libdir/named into bind-chroot tmpfiles (RHEL-132053)
* Fri Dec 12 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-14
- Create /var/named directories for bind-chroot (RHEL-132053)
* Fri Oct 31 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-13
- Fix upstream reported regression in recent CVE fix (CVE-2025-8677)
* Thu Oct 23 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-12
- Refuse malformed DNSKEY records (CVE-2025-8677)
- Address various spoofing attacks (CVE-2025-40778)
- Prevent cache poisoning due to weak PRNG (CVE-2025-40780)
* Fri Oct 03 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-11
- Move named.* files from /var/named into /usr/share/named
- Move named.ca into /etc/named.ca
* Tue Sep 16 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-10
- Fix failures in idna system test (RHEL-66172)
* Fri Sep 12 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-9
- Decode IDN names on input in all situations in utilities (RHEL-66172)
* Fri Sep 12 2025 Petr Menšík <<pemensik@redhat.com>> - 32:9.18.33-8
- logrotate: skip if empty and remove old variants (RHEL-113942)
* Wed Jul 09 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-7
- Add runtime tunable limit by environment NAMED_MAXADDITIONAL (RHEL-84006)
* Fri Jun 20 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-6
- Change additional NS to be served partially (RHEL-84006)
* Tue Jun 10 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-5
- Backport support for OpenSSL provider required for PKCS11 labels
* Tue Jun 10 2025 Petr Mensik <pemensik@redhat.com> - 32:9.18.33-4
- Prevent name.c:670 attributes assertion failed (RHEL-30407)
- Add extra checks for relative names
* Thu Feb 13 2025 Thomas Woerner <twoerner@redhat.com> - 32:9.18.33-3
- Fix upgrade of doc sub package to remove links replaced by directories
(RHEL-48798)
* Sun Feb 02 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-2
- Add nsupdate TLS support (RHEL-77354)
- Include a test for nsupdate changes
* Sun Feb 02 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.33-1
- Update to 9.16.33 (rhbz#2342784)
- Make relative documentation links
- Permanently remove DLZ parts build
* Fri Jan 17 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.32-2
- Add sysusers named user creation (rhbz#2105415)
* Thu Dec 12 2024 Petr Menšík <pemensik@redhat.com> - 32:9.18.32-1
- Update to 9.18.32 (RHEL-48798)
- Remove CHANGES file from package
* Tue Oct 29 2024 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-1
- Update to 9.18.29 (RHEL-48798)
* Tue Oct 29 2024 Petr Menšík <pemensik@redhat.com> - 32:9.18.28-1
- Update to 9.18.28 (RHEL-48798)
* Tue Oct 29 2024 Petr Menšík <pemensik@redhat.com> - 32:9.18.27-6
- Update to 9.18.27 (RHEL-48798)
* Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 32:9.18.21-7
- Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018
* Tue Oct 08 2024 Petr Menšík <pemensik@redhat.com> - 32:9.18.21-6
- Make OpenSSL engine support optional and disabled (RHEL-22408)
/usr/bin/dnssec-cds /usr/bin/dnssec-dsfromkey /usr/bin/dnssec-importkey /usr/bin/dnssec-keyfromlabel /usr/bin/dnssec-keygen /usr/bin/dnssec-revoke /usr/bin/dnssec-settime /usr/bin/dnssec-signzone /usr/bin/dnssec-verify /usr/lib/.build-id /usr/lib/.build-id/17 /usr/lib/.build-id/17/5625f4ef7fdeb7b3e2b79a6bb8fc22a4b0977e /usr/lib/.build-id/30 /usr/lib/.build-id/30/fde73a790b73519300b024a2005d9719f66706 /usr/lib/.build-id/37 /usr/lib/.build-id/37/4f8bc7d83174a79f64b4d166f27f11b9d08867 /usr/lib/.build-id/7b /usr/lib/.build-id/7b/f8fcd7d7c2684e0c855a202f000d4bccbdcdb6 /usr/lib/.build-id/8c/04d3f5895d0641c84d8f8c09b17ce97f616fd5 /usr/lib/.build-id/8d /usr/lib/.build-id/8d/4e2ea1ca5b75cad7c5116f4ba8ef032df66678 /usr/lib/.build-id/a3 /usr/lib/.build-id/a3/f3eddb1524290cbfc2e36d05c8029f6aa19ff7 /usr/lib/.build-id/d6 /usr/lib/.build-id/d6/ac2e78a71c2ab387a8ade18776530e34a035bd /usr/lib/.build-id/e0 /usr/lib/.build-id/e0/7cb4c33be0551679d660fc639aca0f2a3f483f /usr/share/man/man1/dnssec-cds.1.gz /usr/share/man/man1/dnssec-dsfromkey.1.gz /usr/share/man/man1/dnssec-importkey.1.gz /usr/share/man/man1/dnssec-keyfromlabel.1.gz /usr/share/man/man1/dnssec-keygen.1.gz /usr/share/man/man1/dnssec-revoke.1.gz /usr/share/man/man1/dnssec-settime.1.gz /usr/share/man/man1/dnssec-signzone.1.gz /usr/share/man/man1/dnssec-verify.1.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Oct 1 04:17:07 2026