Search CVE reports


Toggle filters

21 – 30 of 120 results


CVE-2026-11605

Medium priority
Fixed

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Not affected Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected Not affected Not affected
bind9-libs Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-11331

Medium priority

Some fixes available 3 of 12

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-10822

Medium priority

Some fixes available 3 of 12

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-10723

Medium priority

Some fixes available 3 of 12

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Needs evaluation Needs evaluation
isc-dhcp Needs evaluation Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-14258

Medium priority
Needs evaluation

A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56117

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56116

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56115

Medium priority
Needs evaluation

Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56114

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-56113

Medium priority
Needs evaluation

dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603...

1 affected package

dhcpcd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dhcpcd Needs evaluation Needs evaluation Not in release
Show less packages