CyberSecurity News
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
AI summary
The Internet Systems Consortium has released updates for its BIND 9 open-source DNS server software, addressing 14 security flaws. The updates, versions 9.20.29 and 9.21.26, were released in response to vulnerabilities disclosed on September 16. One of the flaws allows an unauthenticated sender to crash the server process with a single request containing an invalid SIG, affecting servers that handle DNS-over-HTTPS queries. This specific vulnerability can be exploited without the need for credentials. The updates aim to fix these security issues in the BIND 9 software.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

