-
Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.16.23-0.22.12
- Fix NSEC3 signer validation (CVE-2026-10723)
- Resolves: RHEL-213499
-
Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.16.23-0.22.11
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)
- Resolves: RHEL-213313
-
Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.16.23-0.22.10
- Fix CVE-2026-11622: reference-counted DNS cache slab headers
- Resolves: RHEL-213396
-
Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.16.23-0.22.9
- Fix CVE-2026-11721: RRSIG labels validation and out-of-zone signing
- Add new unit test
- Resolves: RHEL-213406
-
Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.16.23-0.22.8
- Fix RPZ name-too-long wildcard expansion (CVE-2026-11331)
- Add upstream rpz system test
- Resolves: RHEL-213478
-
Thu Jul 23 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.16.23-0.22.7
- Fix CVE-2026-13204: ensure NSEC/NSEC3 has matching RRSIG
- Resolves: RHEL-213478
-
Mon May 25 2026 Petr Menšík <pemensik@redhat.com> - 32:9.16.23-0.22.6
- Fix GSS-API resource leak (CVE-2026-3039)
- Invalid handling of CLASS != IN (CVE-2026-5946)
-
Fri Mar 27 2026 Petr Menšík <pemensik@redhat.com> - 32:9.16.23-0.22.5
- Prevent Denial of Service via maliciously crafted DNSSEC-validated zone
(CVE-2026-1519)
-
Wed Oct 29 2025 Petr Menšík <pemensik@redhat.com> - 32:9.16.23-0.22.4
- Prevent cache poisoning due to weak PRNG (CVE-2025-40780)
- Address various spoofing attacks (CVE-2025-40778)
- Replace downstream fixes with upstream changes
-
Wed Aug 13 2025 Petr Menšík <pemensik@redhat.com>
- Update addresses of b.root-servers.net (RHEL-18449) - 32:9.16.23-0.22.3