From patchwork Thu Jul 23 05:21:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: auh@yoctoproject.org X-Patchwork-Id: 93301 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3D2DAC531CD for ; Thu, 23 Jul 2026 05:21:28 +0000 (UTC) Received: from a27-45.smtp-out.us-west-2.amazonses.com (a27-45.smtp-out.us-west-2.amazonses.com [54.240.27.45]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.17384.1784784079983933329 for ; Wed, 22 Jul 2026 22:21:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@yoctoproject.org header.s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky header.b=jNeY557J; dkim=pass header.i=@amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=CkfedPaz; spf=pass (domain: us-west-2.amazonses.com, ip: 54.240.27.45, mailfrom: 0101019f8d6bc7e3-6cc57616-83f7-43c0-ac92-2aee52c1e164-000000@us-west-2.amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=lvjh2tk576v2ro5mi6k4dt3mc6wpqbky; d=yoctoproject.org; t=1784784079; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date; bh=z360KM4XoPHRJYRRhDs4HB5v8ZGGtwTP9zWBiZFGPQ8=; b=jNeY557JjRLrGWPISPiyPOqN4dHoHAMyGGs5GUvVeKSdwDT6XVFO+83YLpoqZvzY RWaGTMDLjCQVnmqa3DScIfTUw1Zx0dwUtjZHaSaGwAPBXt52C6B+i4jyomVIWN6qGaq mOCm1s0Y7gdhSNWFK3OGaCXMuDd0Ps6/+k9NREv8= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=hsbnp7p3ensaochzwyq5wwmceodymuwv; d=amazonses.com; t=1784784079; h=Content-Type:MIME-Version:From:To:Subject:Message-Id:Date:Feedback-ID; bh=z360KM4XoPHRJYRRhDs4HB5v8ZGGtwTP9zWBiZFGPQ8=; b=CkfedPazKyxPO5DJAmw0CFx4VH+iyahn95ELvdY4ltrt0JHtEYXMFEU1Vf/UDFwx SEN9NecegN6RKv+N9JaJpGbepOL40wLdtzcjystws8HbXy9p0180/cyuBrqu+rP5EaI W7oyLhg6QFiZkZ+ctBBFVuE5yTXG932ELClDtqWQ= MIME-Version: 1.0 From: auh@yoctoproject.org To: openembedded-core@lists.openembedded.org Subject: [AUH] bind: upgrading to 9.20.26 SUCCEEDED Message-ID: <0101019f8d6bc7e3-6cc57616-83f7-43c0-ac92-2aee52c1e164-000000@us-west-2.amazonses.com> Date: Thu, 23 Jul 2026 05:21:18 +0000 Feedback-ID: ::1.us-west-2.9np3MYPs3fEaOBysGKSlUD4KtcmPijcmS9Az2Hwf7iQ=:AmazonSES X-SES-Outgoing: 2026.07.23-54.240.27.45 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 23 Jul 2026 05:21:28 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241767 Hello, this email is a notification from the Auto Upgrade Helper that the automatic attempt to upgrade the recipe(s) *bind* to *9.20.26* has Succeeded. Next steps: - apply the patch: git am 0001-bind-upgrade-9.20.24-9.20.26.patch - check the changes to upstream patches and summarize them in the commit message, - compile an image that contains the package - perform some basic sanity tests - amend the patch and sign it off: git commit -s --reset-author --amend - send it to the appropriate mailing list Alternatively, if you believe the recipe should not be upgraded at this time, you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that automatic upgrades would no longer be attempted. Please review the attached files for further information and build/update failures. Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler Regards, The Upgrade Helper -- >8 -- From f67c43bdbb20b66c11879e91ac5be89e8f66c725 Mon Sep 17 00:00:00 2001 From: Upgrade Helper Date: Thu, 23 Jul 2026 05:12:31 +0000 Subject: [PATCH] bind: upgrade 9.20.24 -> 9.20.26 Source: doc/changelog/changelog-9.20.25.rst, doc/changelog/changelog-9.20.26.rst BIND 9.20.25 ------------ .. note:: The BIND 9.20.25 release was withdrawn after the discovery of a regression in a security fix in it during pre-release testing. BIND 9.20.26 ------------ Security Fixes ~~~~~~~~~~~~~~ - [CVE-2026-11331] Fix handling of rpz CNAME expansion that returns name too long. ``b950da5f625`` Previously, if the expansion of a wildcard CNAME RPZ policy resulted in a name that exceeded the length limit, a self referential CNAME and the original address record were returned, allowing the policy to be bypassed. In branches up to 9.20, this also left query processing in an inconsistent state which could trigger an assertion failure. We now return a YXDOMAIN response, without the address. ISC would like to thank Laith Mash'al (0xmshal) for bringing this issue to our attention. :gl:`#5856` - [CVE-2026-11721] Invalid signed wildcard records were being accepted. ``249752cd72d`` Signed wildcard responses in which the Labels field in the `RRSIG` record was less than the number of labels in the Signer Name field were being incorrectly accepted. This in turn broke `synth-from-dnssec`, which depends on such records being correctly validated. This has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention. :gl:`#5871` - [CVE-2026-13321] Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. ``6fbc963d4af`` A malicious zone with out-of-zone NSEC next owner names can cause a DNSSEC validating resolver to cache such record and, if `synth-from-dnssec` is enabled, to generate negative answers for any zone that is covered by the range. ISC would like to thank Qifan Zhang of Palo Alto Networks for reporting the issue. :gl:`#5873` - [CVE-2026-10723] Correct verification of NSEC3 signer name. ``df3abfc3184`` BIND 9 accepted child-zone NSEC3 records where the first label equals the hash of the parent zone as valid parent-zone closest encloser proofs. This has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue. :gl:`#5874` - [CVE-2026-12617] Do no assert for some specifics CNAME and DNAME queries. ``d75d1e93958`` A bug in the resolver's handling of certain cached DNAME and CNAME responses could cause named to trigger an assertion failure and exit. An attacker controlling a domain name and the authoritative DNS server it is hosted on could exploit this behavior to cause a denial-of-service. This vulnerability has been fixed. ISC thanks Qifan Zhang of Palo Alto Networks for bringing this issue to our attention. :gl:`#5946` - [CVE-2026-10822] Malformed DNSKEY records could trigger an assertion. ``a1777ce7ee0`` Previously, `dns_name_fromwire()` did not honor the record boundary when reading names from the wire, allowing malformed records to be accepted when they should not have been [Changelog truncated as it exceeds 3000 characters; the full changelog can be found in an attachment to the AUH email] --- .../bind/bind/0001-avoid-start-failure-with-bind-user.patch | 2 +- .../0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch | 2 +- ...01-named-lwresd-V-and-start-log-hide-build-options.patch | 4 ++-- ...nd-ensure-searching-for-json-headers-searches-sysr.patch | 6 +++--- meta/recipes-connectivity/bind/bind/conf.patch | 2 +- .../bind/bind/init.d-add-support-for-read-only-rootfs.patch | 2 +- .../bind/bind/make-etc-initd-bind-stop-work.patch | 2 +- .../bind/{bind_9.20.24.bb => bind_9.20.26.bb} | 2 +- 8 files changed, 11 insertions(+), 11 deletions(-) rename meta/recipes-connectivity/bind/{bind_9.20.24.bb => bind_9.20.26.bb} (97%) diff --git a/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch b/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch index 806ca9c5bd..4bc8b4630c 100644 --- a/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch +++ b/meta/recipes-connectivity/bind/bind/0001-avoid-start-failure-with-bind-user.patch @@ -1,4 +1,4 @@ -From e4886a825c82a7d6f4bd6badeeaeea700e429483 Mon Sep 17 00:00:00 2001 +From cf7537b0ddccefd04dcb82ca470262ce61afb252 Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Mon, 15 Oct 2018 16:55:09 +0800 Subject: [PATCH] avoid start failure with bind user diff --git a/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch b/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch index 9b2870bd38..c9dbff3817 100644 --- a/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch +++ b/meta/recipes-connectivity/bind/bind/0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch @@ -1,4 +1,4 @@ -From e5f31670d79906033209d6b30d925dcd0324c95a Mon Sep 17 00:00:00 2001 +From fa7670386a1643de5b976f6928e42662b968d807 Mon Sep 17 00:00:00 2001 From: Khem Raj Date: Fri, 10 Apr 2026 23:33:49 +0000 Subject: [PATCH] m4: Backport ax_prog_cc_for_build.m4 macros diff --git a/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch b/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch index 1bbf17b12e..740d1e98e2 100644 --- a/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch +++ b/meta/recipes-connectivity/bind/bind/0001-named-lwresd-V-and-start-log-hide-build-options.patch @@ -1,4 +1,4 @@ -From c18ad4de676ed9350837c4c90a5e53a941712ba4 Mon Sep 17 00:00:00 2001 +From 41901eaecf617abf8f2608e07baa775c75436a15 Mon Sep 17 00:00:00 2001 From: Hongxu Jia Date: Mon, 27 Aug 2018 21:24:20 +0800 Subject: [PATCH] `named/lwresd -V' and start log hide build options @@ -20,7 +20,7 @@ Signed-off-by: Armin Kuster 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index c845a8e..d065454 100644 +index af020f0..f461229 100644 --- a/configure.ac +++ b/configure.ac @@ -35,7 +35,7 @@ AC_DEFINE([PACKAGE_VERSION_EXTRA], ["][bind_VERSION_EXTRA]["], [BIND 9 Extra par diff --git a/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch b/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch index 352a2f1bc1..3c7f09d6bd 100644 --- a/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch +++ b/meta/recipes-connectivity/bind/bind/bind-ensure-searching-for-json-headers-searches-sysr.patch @@ -1,4 +1,4 @@ -From 6f0289bc8ee2c5a6d386d6d6921875219b268951 Mon Sep 17 00:00:00 2001 +From 6a7536c66832e4d99d7d156256b1a98d9497c7de Mon Sep 17 00:00:00 2001 From: Paul Gortmaker Date: Tue, 9 Jun 2015 11:22:00 -0400 Subject: [PATCH] bind: ensure searching for json headers searches sysroot @@ -32,10 +32,10 @@ Signed-off-by: Paul Gortmaker 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/configure.ac b/configure.ac -index 7b9a63b..c845a8e 100644 +index f47ce7b..af020f0 100644 --- a/configure.ac +++ b/configure.ac -@@ -865,7 +865,7 @@ AS_CASE([$with_lmdb], +@@ -872,7 +872,7 @@ AS_CASE([$with_lmdb], [no],[], [auto|yes], [PKG_CHECK_MODULES([LMDB], [lmdb], [ac_lib_lmdb_found=yes], diff --git a/meta/recipes-connectivity/bind/bind/conf.patch b/meta/recipes-connectivity/bind/bind/conf.patch index c7f6941908..8e82c57035 100644 --- a/meta/recipes-connectivity/bind/bind/conf.patch +++ b/meta/recipes-connectivity/bind/bind/conf.patch @@ -1,4 +1,4 @@ -From d308d9b835f4ad11e5824e7333668792980c1357 Mon Sep 17 00:00:00 2001 +From 352339af9e6cd9fc03caff09a1b295f26dfadc32 Mon Sep 17 00:00:00 2001 From: Qing He Date: Tue, 30 Nov 2010 13:35:42 +0800 Subject: [PATCH] bind: add new recipe diff --git a/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch b/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch index ec9eec6d3e..73e39002ca 100644 --- a/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch +++ b/meta/recipes-connectivity/bind/bind/init.d-add-support-for-read-only-rootfs.patch @@ -1,4 +1,4 @@ -From 23b997fc6276a527e1cf36312cd121170c15978c Mon Sep 17 00:00:00 2001 +From 75923521847618392e20fd9abd3245618b77c8f7 Mon Sep 17 00:00:00 2001 From: Chen Qi Date: Thu, 27 Mar 2014 02:34:41 +0000 Subject: [PATCH] init.d: add support for read-only rootfs diff --git a/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch b/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch index 54d948bb17..568e4f2e59 100644 --- a/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch +++ b/meta/recipes-connectivity/bind/bind/make-etc-initd-bind-stop-work.patch @@ -1,4 +1,4 @@ -From f5932fde97bb5b47144d926219f3903145a71185 Mon Sep 17 00:00:00 2001 +From 0224516d7bd100b6ea7b4fafdd07b42aa96cb0ba Mon Sep 17 00:00:00 2001 From: Roy Li Date: Thu, 15 Nov 2012 02:27:54 +0000 Subject: [PATCH] bind: make "/etc/init.d/bind stop" work diff --git a/meta/recipes-connectivity/bind/bind_9.20.24.bb b/meta/recipes-connectivity/bind/bind_9.20.26.bb similarity index 97% rename from meta/recipes-connectivity/bind/bind_9.20.24.bb rename to meta/recipes-connectivity/bind/bind_9.20.26.bb index 3c5acc972b..21ffad7bad 100644 --- a/meta/recipes-connectivity/bind/bind_9.20.24.bb +++ b/meta/recipes-connectivity/bind/bind_9.20.26.bb @@ -21,7 +21,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \ file://0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch \ " -SRC_URI[sha256sum] = "989fef1fc88ea59d04cd86f854dca5a4616a20a9968bcdde3c1a3668ab36be08" +SRC_URI[sha256sum] = "55248def0f870c4c46b3de72978ea972615131516663188a4564dca1d20bf350" UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/" # follow the ESV versions divisible by 2