Red Hat Product Errata RHSA-2026:24339 - Security Advisory Issued: 2026-06-08 Updated: 2026-06-08 RHSA-2026:24339 - Security Advisory Overview Updated Packages Synopsis Important: bind security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for bind is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly. Security Fix(es): bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2479767 - CVE-2026-3039 bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation BZ - 2479771 - CVE-2026-5946 bind: BIND: Denial of Service via specially crafted DNS messages CVEs CVE-2026-3039 CVE-2026-5946 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM bind-9.11.36-16.el8_10.8.src.rpm SHA-256: 9c408861d4285b732f2ced9d32f90355cf44fe70c64c0aed93f4b021ccb37cb9 x86_64 bind-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 6282e2aed7aac72b9d3a2ff42fe5bfcf9f53ca2cd4cc0bc5bc57fc2f7673d260 bind-chroot-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: f874dd9c491b967e056b935b42ba417bd73b5fdc056fa6a14cbfdb12f1f51b88 bind-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 9bfff23dba6b7e65defdae87f10a15dd26b09ce0c1bbc21673a13ee469b52c06 bind-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 9bfff23dba6b7e65defdae87f10a15dd26b09ce0c1bbc21673a13ee469b52c06 bind-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 8e1ce8a262b620aba4ff7f2e38c457186c1073cd0cbba47eb31ad22e17860b68 bind-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 8e1ce8a262b620aba4ff7f2e38c457186c1073cd0cbba47eb31ad22e17860b68 bind-debugsource-9.11.36-16.el8_10.8.i686.rpm SHA-256: 324a5bbbf1c6627cf9194278b8c13564f5b3924569b73b49abc6733b28dc9ede bind-debugsource-9.11.36-16.el8_10.8.i686.rpm SHA-256: 324a5bbbf1c6627cf9194278b8c13564f5b3924569b73b49abc6733b28dc9ede bind-debugsource-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: b8f6cfe2ee1863e7900c85f8f2711e8c25ad6e9fd3cdb15287ba6e6af87d8ed8 bind-debugsource-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: b8f6cfe2ee1863e7900c85f8f2711e8c25ad6e9fd3cdb15287ba6e6af87d8ed8 bind-devel-9.11.36-16.el8_10.8.i686.rpm SHA-256: 04db9e0540b4d15bd54451772335ac65c4fecd33f7d72c2723d4c46d7ebc085d bind-devel-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 47252c2c3fdece2158388f50ebffeef0bac05b67278bc7b22e8e2a44122c516f bind-export-devel-9.11.36-16.el8_10.8.i686.rpm SHA-256: 9dd6f192e6901dc0e5a5300f86adc895ab73bdef7d585d7d4552a06a2797092c bind-export-devel-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: bf10808d97365ceb1f87a436135076044de7b8568870c75c323d1d3e4742810e bind-export-libs-9.11.36-16.el8_10.8.i686.rpm SHA-256: 7b88bf31a823c07bf502a6af935cfc922f1f25f45a5fe293ebfa17506970d165 bind-export-libs-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 3e395e237bafedafeaed5370703d89b2ce72112392e5600be1964eedcb07e65e bind-export-libs-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: f51c00f720e03f99f8ee5332f70805b0545ecd2cb328803d6a99599fc99bc2ca bind-export-libs-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: f51c00f720e03f99f8ee5332f70805b0545ecd2cb328803d6a99599fc99bc2ca bind-export-libs-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: d06a229cfd1d9448238a63d7ce351c75482b65f4a185ccc330b527196572a2d5 bind-export-libs-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: d06a229cfd1d9448238a63d7ce351c75482b65f4a185ccc330b527196572a2d5 bind-libs-9.11.36-16.el8_10.8.i686.rpm SHA-256: 307038f82f3033d364ccbd27b6ed6e75ed1a463c9683855c43bf40812a077f99 bind-libs-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 8b46b67fc4c0854ea8335dc23c73cf4786b50b8bf7b15fb7855f91e0d9f6b426 bind-libs-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: a7097e27829709e4a501e6127f9cbee5ee29187d4b9006292dddefd54fed849b bind-libs-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: a7097e27829709e4a501e6127f9cbee5ee29187d4b9006292dddefd54fed849b bind-libs-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 958f6c717b0b9807421bc2c74e7e831bee75cfd61edbedbf729f08cbd2085a08 bind-libs-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 958f6c717b0b9807421bc2c74e7e831bee75cfd61edbedbf729f08cbd2085a08 bind-libs-lite-9.11.36-16.el8_10.8.i686.rpm SHA-256: 3cd1e5742a4765ec28af127051d7c77b108ab5bea8ec3582474c2a13d4686547 bind-libs-lite-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 1ff10d0be2a72e7fca46fb01953738444c790b8041c33c0541d91e10389e1bb0 bind-libs-lite-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 31960273f18ebfc1b05182c3f22804d7bdb4c2aa8c269b78b75fde01a6db967a bind-libs-lite-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 31960273f18ebfc1b05182c3f22804d7bdb4c2aa8c269b78b75fde01a6db967a bind-libs-lite-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: d2bdfcf9cceb2d248a070ca8012daeb709591a209bc5e5b5759142e873043a05 bind-libs-lite-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: d2bdfcf9cceb2d248a070ca8012daeb709591a209bc5e5b5759142e873043a05 bind-license-9.11.36-16.el8_10.8.noarch.rpm SHA-256: b2ad05fd87527abb36aa907c5f2b73dab39c6eec19bc1b5e0ac38b339c79c909 bind-lite-devel-9.11.36-16.el8_10.8.i686.rpm SHA-256: 49f48281a34fbc42e038477cf8c70464fc7a4eaa9126ed567becfaf302e8808f bind-lite-devel-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 41f6bfeb75aafd4d0f08b5e8e952f0109e24aab5c21d03f69541384cc104de01 bind-pkcs11-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 72a53d24760b4b8abd771724acc84d28fcefee1ec792c7401dfc451ca46f4630 bind-pkcs11-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 7e5eca75615e00ffe713cce44fd5b668b8359995fe436a41750ef7e4416045f5 bind-pkcs11-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 7e5eca75615e00ffe713cce44fd5b668b8359995fe436a41750ef7e4416045f5 bind-pkcs11-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 2af7199af13be0659eca2efdce87c43848a06ff3986f7dfa0c5ad6cf00139269 bind-pkcs11-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 2af7199af13be0659eca2efdce87c43848a06ff3986f7dfa0c5ad6cf00139269 bind-pkcs11-devel-9.11.36-16.el8_10.8.i686.rpm SHA-256: a6392ebe5bcbe063f7a52fef5302384661d9a322f63dd948cb5792fe7bf5ab7b bind-pkcs11-devel-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 79af0b73fb64f921b978e4a322db9eac2f4735e0eff73cda354836b06c9be583 bind-pkcs11-libs-9.11.36-16.el8_10.8.i686.rpm SHA-256: ecd9f0f277c3abde09beeb4b487c4a0fea6539040a86250c4070ae5d59d07c23 bind-pkcs11-libs-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 49ca02cf39b4f80c01d1232c856603750a73259c39ddb3c0f551110306b89017 bind-pkcs11-libs-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 6b9a96e9975d5b221b7258a7c02883f7e3c192e7c9be3cb643f07e8262aec389 bind-pkcs11-libs-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 6b9a96e9975d5b221b7258a7c02883f7e3c192e7c9be3cb643f07e8262aec389 bind-pkcs11-libs-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 5adc5929d24b391c5c37db72ebab7c17c49f4b5e0b0ca600428c681ecfdcef07 bind-pkcs11-libs-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 5adc5929d24b391c5c37db72ebab7c17c49f4b5e0b0ca600428c681ecfdcef07 bind-pkcs11-utils-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 0a0c2400ff4c493700419d57b2714aeddc49173b78c819b701bcfdfaa3376d9c bind-pkcs11-utils-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 926fa0ecd8e5e50a6b59a1b6b57e450b992cfabf45a7383bd88ef01ed2e52ca9 bind-pkcs11-utils-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 926fa0ecd8e5e50a6b59a1b6b57e450b992cfabf45a7383bd88ef01ed2e52ca9 bind-pkcs11-utils-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 190f86976e2e70d946da276882a1ee86e0f30efb92ebdc4cab3f9893e1c473e0 bind-pkcs11-utils-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 190f86976e2e70d946da276882a1ee86e0f30efb92ebdc4cab3f9893e1c473e0 bind-sdb-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 3977eb94fe7cec8d62cf7ae45f5677a7dd6e86f5e2d0b65492523ac4033bba3b bind-sdb-chroot-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: b5ddb37d5c3d8824941e9592fa922f75e37a91d20a5df4be202fb38060916743 bind-sdb-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 4f865ac22f8e5d07befe3e38bcd3143d338223e88e1438e55e4492345f9f79f8 bind-sdb-debuginfo-9.11.36-16.el8_10.8.i686.rpm SHA-256: 4f865ac22f8e5d07befe3e38bcd3143d338223e88e1438e55e4492345f9f79f8 bind-sdb-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 77b102a6aefbe04261a4039b426676f5f1a4977c3d61d8ff5a79012d272bbb3f bind-sdb-debuginfo-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: 77b102a6aefbe04261a4039b426676f5f1a4977c3d61d8ff5a79012d272bbb3f bind-utils-9.11.36-16.el8_10.8.x86_64.rpm SHA-256: a9c90ac0a74e9b14a0641e7ba4d845d3727ca88b516e8ade66
This Red Hat advisory addresses two Important-severity vulnerabilities in BIND 9: CVE-2026-3039, which causes memory exhaustion during GSS-API TKEY negotiation, and CVE-2026-5946, a Denial of Service via specially crafted DNS messages, both with a CVSS 3.1 score of 7.5 (High). Affected versions include BIND 9.0.0 through 9.16.50, 9.18.0 through <9.18.49, 9.20.0 through <9.20.23, and 9.21.0 through <9.21.22. The fixed versions are BIND 9.18.49, 9.20.23, and 9.21.22.