Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

bind9.18-dnssec-utils-9.18.29-26.el9 RPM for aarch64

From CentOS Stream 9 AppStream for aarch64

Name: bind9.18-dnssec-utils Distribution: CentOS
Version: 9.18.29 Vendor: CentOS
Release: 26.el9 Build date: Wed Sep 2 16:15:33 2026
Group: Unspecified Build host: aarch64-03.stream.rdu2.redhat.com
Size: 715074 Source RPM: bind9.18-9.18.29-26.el9.src.rpm
Packager: builder@centos.org
Url: https://www.isc.org/downloads/bind/
Summary: DNSSEC keys and zones management utilities
bind9.18-dnssec-utils contains a collection of utilities for editing
DNSSEC keys and BIND zone files. These tools provide generation,
revocation and verification of keys and DNSSEC signatures in zone files.

You should install bind9.18-dnssec-utils if you need to sign a DNS zone
or maintain keys for it.

Provides

Requires

License

MPL-2.0 AND ISC AND MIT AND BSD-3-Clause AND BSD-2-Clause

Changelog

* Wed Sep 02 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-26
  - Add new root key 38696 into package files (RHEL-131887)
  - Update built-in anchors in delv and named
* Thu Aug 27 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-25
  - Remove downstream introduced double-free (CVE-2026-5950)
* Wed Aug 19 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-24
  - Avoid unbounded recursion loop (CVE-2026-5950)
  - Limit overlapping addresses resolver usage (CVE-2026-3592)
* Sat Jul 25 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.29-23
  - Fix NSEC3 signer validation (CVE-2026-10723)
* Fri Jul 24 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.29-22
  - Reject out-of-zone NSEC next owner names (CVE-2026-13321)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.29-21
  - Fix cache exhaustion via dns_slabheaders (CVE-2026-11622)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.29-20
  - Reject invalid signed wildcard records (CVE-2026-11721)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.29-19
  - Fix RPZ wildcard expansion self-referential CNAME (CVE-2026-11331)
* Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.18.29-18
  - Fix assertion crash via unsigned NSEC/NSEC3 (CVE-2026-13204,
    RHEL-213495)
* Mon May 25 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-17
  - Fix GSS-API resource leak (CVE-2026-3039)
  - Invalid handling of CLASS != IN (CVE-2026-5946)
* Fri Mar 27 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-16
  - Prevent Denial of Service via maliciously crafted DNSSEC-validated zone
    (CVE-2026-1519)
  - Correct backport issue in the patch (CVE-2026-1519)
* Thu Feb 26 2026 Fedor Vorobev <fvorobev@redhat.com> - 32:9.18.29-15
  - Backport fixes for stale CNAME chains. (RHEL-86172)
* Fri Jan 30 2026 Fedor Vorobev <fvorobev@redhat.com> - 32:9.18.29-14
  - Backport fix for manual DNSSEC key rolllovers. (RHEL-144422)
* Thu Jan 29 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-13
  - Correct changelog version of previous change
* Wed Jan 28 2026 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-12
  - Add forgotten _libdir/named into bind-chroot tmpfiles (RHEL-132053)
* Fri Dec 12 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-11
  - Add sysusers named user creation (RHEL-132053)
* Fri Dec 12 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-10
  - Add missing bind-chroot subdirectories
* Fri Dec 12 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-9
  - Create /var/named directories for bind-chroot (RHEL-132053)
* Fri Oct 31 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-8
  - Copy named.* files from /usr/share/named into var/named
* Fri Oct 31 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-7
  - Fix upstream reported regression in recent CVE fix (CVE-2025-8677)
  - Add upstream created test to this regression
* Thu Oct 23 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-6
  - Refuse malformed DNSKEY records (CVE-2025-8677)
  - Address various spoofing attacks (CVE-2025-40778)
  - Prevent cache poisoning due to weak PRNG (CVE-2025-40780)
* Fri Sep 12 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-5
  - logrotate: skip if empty and remove old variants (RHEL-113942)
* Tue Jun 10 2025 Petr Mensik <pemensik@redhat.com> - 32:9.18.29-4
  - Prevent name.c:670 attributes assertion failed (RHEL-30407)
  - Add extra checks for relative names
* Mon Feb 03 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-3
  - Limit additional section records CPU processing (CVE-2024-11187)
  - Read HTTPS requests in limited chunks and prevent overload (CVE-2024-12705)
* Mon Jan 27 2025 Petr Menšík <pemensik@redhat.com> - 32:9.18.29-2
  - Backport nsupdate TLS support into 9.18 (RHEL-76331)
  - Update nsupdate manual about new TLS options
  - Test nsupdate TLS support

Files

/usr/bin/dnssec-cds
/usr/bin/dnssec-dsfromkey
/usr/bin/dnssec-importkey
/usr/bin/dnssec-keyfromlabel
/usr/bin/dnssec-keygen
/usr/bin/dnssec-revoke
/usr/bin/dnssec-settime
/usr/bin/dnssec-signzone
/usr/bin/dnssec-verify
/usr/lib/.build-id
/usr/lib/.build-id/1d
/usr/lib/.build-id/1d/38778b5189acecf8b16cf89c880268b5832e6c
/usr/lib/.build-id/2c
/usr/lib/.build-id/2c/b77f936823b96e181147759ec99f4199a67f5c
/usr/lib/.build-id/3a
/usr/lib/.build-id/3a/de09bcb67651e8e0b675cfe7b780ec2b4a7b42
/usr/lib/.build-id/81
/usr/lib/.build-id/81/dc985350575ac6b250aa69c2fd4fac2da59f64
/usr/lib/.build-id/8a
/usr/lib/.build-id/8a/8a5a45af439adabb6a2179d341b688cc375ab2
/usr/lib/.build-id/98
/usr/lib/.build-id/98/7d32a2f7feab1fa69ed28d668dffef322bf0ec
/usr/lib/.build-id/9a
/usr/lib/.build-id/9a/586149e0f4a7d8b413eb4e428326e9650cac1b
/usr/lib/.build-id/b4
/usr/lib/.build-id/b4/5be4eca16a8751d704352d509a1f2661b4194f
/usr/lib/.build-id/ec
/usr/lib/.build-id/ec/ef2e9b8ce98b5f193595cb264f4de45baf7bdd
/usr/share/man/man1/dnssec-cds.1.gz
/usr/share/man/man1/dnssec-dsfromkey.1.gz
/usr/share/man/man1/dnssec-importkey.1.gz
/usr/share/man/man1/dnssec-keyfromlabel.1.gz
/usr/share/man/man1/dnssec-keygen.1.gz
/usr/share/man/man1/dnssec-revoke.1.gz
/usr/share/man/man1/dnssec-settime.1.gz
/usr/share/man/man1/dnssec-signzone.1.gz
/usr/share/man/man1/dnssec-verify.1.gz


Generated by rpm2html 1.8.1

Fabrice Bellet, Wed Sep 9 05:59:31 2026