@@ -1,4 +1,4 @@
-From e4886a825c82a7d6f4bd6badeeaeea700e429483 Mon Sep 17 00:00:00 2001
+From cf7537b0ddccefd04dcb82ca470262ce61afb252 Mon Sep 17 00:00:00 2001
From: Chen Qi <Qi.Chen@windriver.com>
Date: Mon, 15 Oct 2018 16:55:09 +0800
Subject: [PATCH] avoid start failure with bind user
@@ -1,4 +1,4 @@
-From e5f31670d79906033209d6b30d925dcd0324c95a Mon Sep 17 00:00:00 2001
+From fa7670386a1643de5b976f6928e42662b968d807 Mon Sep 17 00:00:00 2001
From: Khem Raj <khem.raj@oss.qualcomm.com>
Date: Fri, 10 Apr 2026 23:33:49 +0000
Subject: [PATCH] m4: Backport ax_prog_cc_for_build.m4 macros
@@ -1,4 +1,4 @@
-From c18ad4de676ed9350837c4c90a5e53a941712ba4 Mon Sep 17 00:00:00 2001
+From 41901eaecf617abf8f2608e07baa775c75436a15 Mon Sep 17 00:00:00 2001
From: Hongxu Jia <hongxu.jia@windriver.com>
Date: Mon, 27 Aug 2018 21:24:20 +0800
Subject: [PATCH] `named/lwresd -V' and start log hide build options
@@ -20,7 +20,7 @@ Signed-off-by: Armin Kuster <akuster@mvista.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
-index c845a8e..d065454 100644
+index af020f0..f461229 100644
--- a/configure.ac
+++ b/configure.ac
@@ -35,7 +35,7 @@ AC_DEFINE([PACKAGE_VERSION_EXTRA], ["][bind_VERSION_EXTRA]["], [BIND 9 Extra par
@@ -1,4 +1,4 @@
-From 6f0289bc8ee2c5a6d386d6d6921875219b268951 Mon Sep 17 00:00:00 2001
+From 6a7536c66832e4d99d7d156256b1a98d9497c7de Mon Sep 17 00:00:00 2001
From: Paul Gortmaker <paul.gortmaker@windriver.com>
Date: Tue, 9 Jun 2015 11:22:00 -0400
Subject: [PATCH] bind: ensure searching for json headers searches sysroot
@@ -32,10 +32,10 @@ Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
-index 7b9a63b..c845a8e 100644
+index f47ce7b..af020f0 100644
--- a/configure.ac
+++ b/configure.ac
-@@ -865,7 +865,7 @@ AS_CASE([$with_lmdb],
+@@ -872,7 +872,7 @@ AS_CASE([$with_lmdb],
[no],[],
[auto|yes], [PKG_CHECK_MODULES([LMDB], [lmdb],
[ac_lib_lmdb_found=yes],
@@ -1,4 +1,4 @@
-From d308d9b835f4ad11e5824e7333668792980c1357 Mon Sep 17 00:00:00 2001
+From 352339af9e6cd9fc03caff09a1b295f26dfadc32 Mon Sep 17 00:00:00 2001
From: Qing He <qing.he@intel.com>
Date: Tue, 30 Nov 2010 13:35:42 +0800
Subject: [PATCH] bind: add new recipe
@@ -1,4 +1,4 @@
-From 23b997fc6276a527e1cf36312cd121170c15978c Mon Sep 17 00:00:00 2001
+From 75923521847618392e20fd9abd3245618b77c8f7 Mon Sep 17 00:00:00 2001
From: Chen Qi <Qi.Chen@windriver.com>
Date: Thu, 27 Mar 2014 02:34:41 +0000
Subject: [PATCH] init.d: add support for read-only rootfs
@@ -1,4 +1,4 @@
-From f5932fde97bb5b47144d926219f3903145a71185 Mon Sep 17 00:00:00 2001
+From 0224516d7bd100b6ea7b4fafdd07b42aa96cb0ba Mon Sep 17 00:00:00 2001
From: Roy Li <rongqing.li@windriver.com>
Date: Thu, 15 Nov 2012 02:27:54 +0000
Subject: [PATCH] bind: make "/etc/init.d/bind stop" work
similarity index 97%
rename from meta/recipes-connectivity/bind/bind_9.20.24.bb
rename to meta/recipes-connectivity/bind/bind_9.20.26.bb
@@ -21,7 +21,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \
file://0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch \
"
-SRC_URI[sha256sum] = "989fef1fc88ea59d04cd86f854dca5a4616a20a9968bcdde3c1a3668ab36be08"
+SRC_URI[sha256sum] = "55248def0f870c4c46b3de72978ea972615131516663188a4564dca1d20bf350"
UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/"
# follow the ESV versions divisible by 2
Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *bind* to *9.20.26* has Succeeded. Next steps: - apply the patch: git am 0001-bind-upgrade-9.20.24-9.20.26.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From f67c43bdbb20b66c11879e91ac5be89e8f66c725 Mon Sep 17 00:00:00 2001 From: Upgrade Helper <auh@yoctoproject.org> Date: Thu, 23 Jul 2026 05:12:31 +0000 Subject: [PATCH] bind: upgrade 9.20.24 -> 9.20.26 Source: doc/changelog/changelog-9.20.25.rst, doc/changelog/changelog-9.20.26.rst BIND 9.20.25 ------------ .. note:: The BIND 9.20.25 release was withdrawn after the discovery of a regression in a security fix in it during pre-release testing. BIND 9.20.26 ------------ Security Fixes ~~~~~~~~~~~~~~ - [CVE-2026-11331] Fix handling of rpz CNAME expansion that returns name too long. ``b950da5f625`` Previously, if the expansion of a wildcard CNAME RPZ policy resulted in a name that exceeded the length limit, a self referential CNAME and the original address record were returned, allowing the policy to be bypassed. In branches up to 9.20, this also left query processing in an inconsistent state which could trigger an assertion failure. We now return a YXDOMAIN response, without the address. ISC would like to thank Laith Mash'al (0xmshal) for bringing this issue to our attention. :gl:`#5856` - [CVE-2026-11721] Invalid signed wildcard records were being accepted. ``249752cd72d`` Signed wildcard responses in which the Labels field in the `RRSIG` record was less than the number of labels in the Signer Name field were being incorrectly accepted. This in turn broke `synth-from-dnssec`, which depends on such records being correctly validated. This has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention. :gl:`#5871` - [CVE-2026-13321] Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. ``6fbc963d4af`` A malicious zone with out-of-zone NSEC next owner names can cause a DNSSEC validating resolver to cache such record and, if `synth-from-dnssec` is enabled, to generate negative answers for any zone that is covered by the range. ISC would like to thank Qifan Zhang of Palo Alto Networks for reporting the issue. :gl:`#5873` - [CVE-2026-10723] Correct verification of NSEC3 signer name. ``df3abfc3184`` BIND 9 accepted child-zone NSEC3 records where the first label equals the hash of the parent zone as valid parent-zone closest encloser proofs. This has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue. :gl:`#5874` - [CVE-2026-12617] Do no assert for some specifics CNAME and DNAME queries. ``d75d1e93958`` A bug in the resolver's handling of certain cached DNAME and CNAME responses could cause named to trigger an assertion failure and exit. An attacker controlling a domain name and the authoritative DNS server it is hosted on could exploit this behavior to cause a denial-of-service. This vulnerability has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention. :gl:`#5946` - [CVE-2026-10822] Malformed DNSKEY records could trigger an assertion. ``a1777ce7ee0`` Previously, `dns_name_fromwire()` did not honor the record boundary when reading names from the wire, allowing malformed records to be accepted when they should not have been [Changelog truncated as it exceeds 3000 characters; the full changelog can be found in an attachment to the AUH email] --- .../bind/bind/0001-avoid-start-failure-with-bind-user.patch | 2 +- .../0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch | 2 +- ...01-named-lwresd-V-and-start-log-hide-build-options.patch | 4 ++-- ...nd-ensure-searching-for-json-headers-searches-sysr.patch | 6 +++--- meta/recipes-connectivity/bind/bind/conf.patch | 2 +- .../bind/bind/init.d-add-support-for-read-only-rootfs.patch | 2 +- .../bind/bind/make-etc-initd-bind-stop-work.patch | 2 +- .../bind/{bind_9.20.24.bb => bind_9.20.26.bb} | 2 +- 8 files changed, 11 insertions(+), 11 deletions(-) rename meta/recipes-connectivity/bind/{bind_9.20.24.bb => bind_9.20.26.bb} (97%)