-
Mon Jul 27 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.11.36-16.14
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)
-
Mon Jul 27 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.11.36-16.12
- Prevent accepting unsigned NSEC/NSEC3 records (CVE-2026-13204)
-
Mon Jul 27 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.11.36-16.11
- Reject out-of-zone NSEC entries in DNSSEC validation
(CVE-2026-13321)
-
Mon Jul 27 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.11.36-16.10
- Reject RRSIG records with invalid label counts (CVE-2026-11721)
- Add unittest check
-
Mon Jul 27 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 32:9.11.36-16.9
- Add reference counting to cache dns_slabheaders (CVE-2026-11622)
-
Wed May 27 2026 Petr Menšík <pemensik@redhat.com> - 32:9.11.36-16.8
- Fix GSS-API resource leak (CVE-2026-3039)
- Invalid handling of CLASS != IN (CVE-2026-5946)
-
Fri Mar 27 2026 Petr Menšík <pemensik@redhat.com> - 32:9.11.36-16.7
- Denial of Service via maliciously crafted DNSSEC-validated zone
(CVE-2026-1519)
-
Thu Oct 30 2025 Petr Menšík <pemensik@redhat.com> - 32:9.11.36-16.6
- Address various spoofing attacks (CVE-2025-40778)
-
Thu Jul 10 2025 Petr Menšík <pemensik@redhat.com> - 32:9.11.36-16.5
- Add support for max-records-per-type and max-types-per-name options
(RHEL-61936)
- Support reading of new options also in named-checkconf -z, v2
-
Thu Feb 06 2025 Petr Menšík <pemensik@redhat.com> - 32:9.11.36-16.4
- Change patches applying to use -P parameter