Release Info

Advisory: CLSA-2025:1762537520

OS: Debian 10 ELS

Public date: 2025-11-07 17:45:22.832602

Project: bind9

Version: 1:9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1

Errata link: https://errata.tuxcare.com/els_os/debian10els/CLSA-2025-1762537520.html

Changelog

* SECURITY UPDATE: The DNS message parsing code in `named` includes a section whose computational complexity is overly high - debian/patches/CVE-2023-4408.patch: refactoring parsing code - debian/patches/CVE-2023-4408-1.patch: fix DNSSEC test suite - debian/libdns1100.symbols: some function declarations were removed according to the CVE-2023-4408.patch - CVE-2023-4408 * Add patch for enabling automated testing

Update

Update command: apt-get update apt-get --only-upgrade install bind9*

Packages list

bind9_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb bind9-doc_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_all.deb bind9-host_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb bind9utils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb dnsutils_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libbind-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libbind-export-dev_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libbind9-161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libdns-export1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libdns1104_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libirs-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libirs161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libisc-export1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libisc1100_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libisccc-export161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libisccc161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libisccfg-export163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb libisccfg163_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb liblwres161_9.11.5.P4+dfsg-5.1+deb10u11+tuxcare.els1_amd64.deb

CVEs

CVE-2023-4408