Back Linuxsecurity Important Fix for Memory Exhaustion and Security Issues in SUSE BIND
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
## This update for bind fixes the following issues: * CVE-2022-3094: UPDATE message flood may cause `named` to exhaust all available memory (bsc#1207471). * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: invalid handling of `CLASS != IN` (bsc#1265594). * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).
## This update for bind fixes the following issues: * CVE-2022-3094: UPDATE message flood may cause `named` to exhaust all available memory (bsc#1207471). * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: invalid handling of `CLASS != IN` (bsc#1265594). * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).
* CVE-2022-3094 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Announcement ID: SUSE-SU-2026:3517-1 Release Date: 2026-08-06T11:20:17Z Rating: important
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
