@@ -1,4 +1,4 @@
-From 2a3ff2a026c55dc67655baf28e0f4175232ee0ff Mon Sep 17 00:00:00 2001
+From a67ac281cd86d8d9ca27e64a5944deb5578e5087 Mon Sep 17 00:00:00 2001
From: Chen Qi <Qi.Chen@windriver.com>
Date: Mon, 15 Oct 2018 16:55:09 +0800
Subject: [PATCH] avoid start failure with bind user
@@ -1,4 +1,4 @@
-From 77f8fafab0cc91c3ad8fbf1382b1d0f2d2cd99a6 Mon Sep 17 00:00:00 2001
+From 16608520c9d946223404165732eacd79b59de471 Mon Sep 17 00:00:00 2001
From: Khem Raj <khem.raj@oss.qualcomm.com>
Date: Fri, 10 Apr 2026 23:33:49 +0000
Subject: [PATCH] m4: Backport ax_prog_cc_for_build.m4 macros
@@ -1,4 +1,4 @@
-From 49ca7b5432dd6c24541bbde21bca5043cd0c000b Mon Sep 17 00:00:00 2001
+From d925183807ae182cf332124ff5a617d257e184f9 Mon Sep 17 00:00:00 2001
From: Hongxu Jia <hongxu.jia@windriver.com>
Date: Mon, 27 Aug 2018 21:24:20 +0800
Subject: [PATCH] `named/lwresd -V' and start log hide build options
@@ -20,7 +20,7 @@ Signed-off-by: Armin Kuster <akuster@mvista.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
-index c3852ec..3b7a446 100644
+index af020f0..f461229 100644
--- a/configure.ac
+++ b/configure.ac
@@ -35,7 +35,7 @@ AC_DEFINE([PACKAGE_VERSION_EXTRA], ["][bind_VERSION_EXTRA]["], [BIND 9 Extra par
@@ -1,4 +1,4 @@
-From fa165cb4a9dfeb72f0db787decd527e3d587cd4e Mon Sep 17 00:00:00 2001
+From af229781e60d6779c76d5a61d26a4597b2a42f6c Mon Sep 17 00:00:00 2001
From: Paul Gortmaker <paul.gortmaker@windriver.com>
Date: Tue, 9 Jun 2015 11:22:00 -0400
Subject: [PATCH] bind: ensure searching for json headers searches sysroot
@@ -32,10 +32,10 @@ Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com>
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/configure.ac b/configure.ac
-index c6a10f6..c3852ec 100644
+index f47ce7b..af020f0 100644
--- a/configure.ac
+++ b/configure.ac
-@@ -865,7 +865,7 @@ AS_CASE([$with_lmdb],
+@@ -872,7 +872,7 @@ AS_CASE([$with_lmdb],
[no],[],
[auto|yes], [PKG_CHECK_MODULES([LMDB], [lmdb],
[ac_lib_lmdb_found=yes],
@@ -1,4 +1,4 @@
-From 4b9f6f6735340d558d9c9fba9c84d7f99d3cbde2 Mon Sep 17 00:00:00 2001
+From bde3a4cb010f459a9ef92817c7e6e6e2d871794a Mon Sep 17 00:00:00 2001
From: Qing He <qing.he@intel.com>
Date: Tue, 30 Nov 2010 13:35:42 +0800
Subject: [PATCH] bind: add new recipe
@@ -1,4 +1,4 @@
-From 19933be78902d90014f177b5633dd15984bc1bc9 Mon Sep 17 00:00:00 2001
+From 8876e722beda701a0de021360ff381347120c6ff Mon Sep 17 00:00:00 2001
From: Chen Qi <Qi.Chen@windriver.com>
Date: Thu, 27 Mar 2014 02:34:41 +0000
Subject: [PATCH] init.d: add support for read-only rootfs
@@ -1,4 +1,4 @@
-From e429899c34ea8a4f85de428e22ee49c453281e82 Mon Sep 17 00:00:00 2001
+From 26c988eee9d2eae7c7dec8c529176352017b2ce1 Mon Sep 17 00:00:00 2001
From: Roy Li <rongqing.li@windriver.com>
Date: Thu, 15 Nov 2012 02:27:54 +0000
Subject: [PATCH] bind: make "/etc/init.d/bind stop" work
similarity index 97%
rename from meta/recipes-connectivity/bind/bind_9.20.23.bb
rename to meta/recipes-connectivity/bind/bind_9.20.26.bb
@@ -21,7 +21,7 @@ SRC_URI = "https://ftp.isc.org/isc/bind9/${PV}/${BPN}-${PV}.tar.xz \
file://0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch \
"
-SRC_URI[sha256sum] = "5d4475aed3f9e500ef554b2b14d972bdb83d33de214a9b3be92918ea46908371"
+SRC_URI[sha256sum] = "55248def0f870c4c46b3de72978ea972615131516663188a4564dca1d20bf350"
UPSTREAM_CHECK_URI = "https://ftp.isc.org/isc/bind9/"
# follow the ESV versions divisible by 2
Changelog: https://ftp.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html This upgrade fixes the following CVEs: - [CVE-2026-11331] Fix handling of rpz CNAME expansion that returns name too long. Previously, if the expansion of a wildcard CNAME RPZ policy resulted in a name that exceeded the length limit, a self referential CNAME and the original address record were returned, allowing the policy to be bypassed. - [CVE-2026-11721] Invalid signed wildcard records were being accepted. Signed wildcard responses in which the Labels field in the RRSIG record was less than the number of labels in the Signer Name field were being incorrectly accepted. - [CVE-2026-13321] Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. A malicious zone with out-of-zone NSEC next owner names can cause a DNSSEC validating resolver to cache such record and generate negative answers for any zone that is covered by the range. - [CVE-2026-10723] Correct verification of NSEC3 signer name. BIND 9 accepted child-zone NSEC3 records where the first label equals the hash of the parent zone as valid parent-zone closest encloser proofs. - [CVE-2026-12617] Do not assert for some specific CNAME and DNAME queries. A bug in the resolver's handling of certain cached DNAME and CNAME responses could cause named to trigger an assertion failure and exit. - [CVE-2026-10822] Malformed DNSKEY records could trigger an assertion. Previously, dns_name_fromwire() did not honor the record boundary when reading names from the wire, allowing malformed records to be accepted when they should not have been. Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech> --- .../bind/bind/0001-avoid-start-failure-with-bind-user.patch | 2 +- .../0001-m4-Backport-ax_prog_cc_for_build.m4-macros.patch | 2 +- ...01-named-lwresd-V-and-start-log-hide-build-options.patch | 4 ++-- ...nd-ensure-searching-for-json-headers-searches-sysr.patch | 6 +++--- meta/recipes-connectivity/bind/bind/conf.patch | 2 +- .../bind/bind/init.d-add-support-for-read-only-rootfs.patch | 2 +- .../bind/bind/make-etc-initd-bind-stop-work.patch | 2 +- .../bind/{bind_9.20.23.bb => bind_9.20.26.bb} | 2 +- 8 files changed, 11 insertions(+), 11 deletions(-) rename meta/recipes-connectivity/bind/{bind_9.20.23.bb => bind_9.20.26.bb} (97%)