Skip to content
Important Fix for Memory Exhaustion and Security Issues in SUSE BIND

Important Fix for Memory Exhaustion and Security Issues in SUSE BIND

Linuxsecurity LinuxSecurity Advisories August 6, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

## This update for bind fixes the following issues: * CVE-2022-3094: UPDATE message flood may cause `named` to exhaust all available memory (bsc#1207471). * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: invalid handling of `CLASS != IN` (bsc#1265594). * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).

## This update for bind fixes the following issues: * CVE-2022-3094: UPDATE message flood may cause `named` to exhaust all available memory (bsc#1207471). * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: invalid handling of `CLASS != IN` (bsc#1265594). * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).

* CVE-2022-3094 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-10723 ( SUSE ): 8.9

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Announcement ID: SUSE-SU-2026:3517-1 Release Date: 2026-08-06T11:20:17Z Rating: important

Get the latest Linux and open source security news straight to your inbox.