<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:56:00 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:1670 — Important: bind9.18 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:1670</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bind9.18, AlmaLinux:9: bind9.18-chroot, AlmaLinux:9: bind9.18-devel, AlmaLinux:9: bind9.18-dnssec-utils, AlmaLinux:9: bind9.18-doc, AlmaLinux:9: bind9.18-libs, AlmaLinux:9: bind9.18-utils&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: bind9: Many records in the additional section cause CPU exhaustion (CVE-2024-11187)
  * bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load (CVE-2024-12705)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bind9.18, AlmaLinux:9: bind9.18-chroot, AlmaLinux:9: bind9.18-devel, AlmaLinux:9: bind9.18-dnssec-utils, AlmaLinux:9: bind9.18-doc, AlmaLinux:9: bind9.18-libs, AlmaLinux:9: bind9.18-utils&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: bind9: Many records in the additional section cause CPU exhaustion (CVE-2024-11187)
  * bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load (CVE-2024-12705)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:1670</guid>
    </item>
    <item>
      <title>bdu:2025-07734</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07734</link>
      <description>bdu:2025-07734</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07734</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-12705</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-12705</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:stream: bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:stream: bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-12705</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0081 — De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0081</link>
      <description>certfr-2025-avi-0081</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0081</guid>
    </item>
    <item>
      <title>EUVD-2026-214250</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-214250</link>
      <description>EUVD-2026-214250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-214250</guid>
    </item>
    <item>
      <title>fkie_cve-2024-12705</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12705</link>
      <description>&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;#39;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;#39;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-12705</guid>
    </item>
    <item>
      <title>GHSA-gf34-2fpp-vmc4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gf34-2fpp-vmc4</link>
      <description>&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;#39;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;#39;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gf34-2fpp-vmc4</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-12705 — DNS-over-HTTPS implementation suffers from multiple issues under heavy query load</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-12705</link>
      <description>msrc_CVE-2024-12705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-12705</guid>
    </item>
    <item>
      <title>OESA-2025-1105 — bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1105</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: bind&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.(CVE-2024-11187)&lt;/p&gt;
&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;amp;apos;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.(CVE-2024-12705)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: bind&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.(CVE-2024-11187)&lt;/p&gt;
&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;amp;apos;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.(CVE-2024-12705)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1105</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14719-1 — bind-9.20.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14719-1</link>
      <description>&lt;p&gt;bind-9.20.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind-9.20.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14719-1</guid>
    </item>
    <item>
      <title>RHSA-2025:1670 — Red Hat Security Advisory: bind9.18 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:1670</link>
      <description>&lt;p&gt;bind: bind9: Many records in the additional section cause CPU exhaustion bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind: bind9: Many records in the additional section cause CPU exhaustion bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:1670</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0355-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0355-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0355-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-12705</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12705</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp, Ubuntu:25.10: isc-dhcp, Ubuntu:26.04:LTS: isc-dhcp&lt;/p&gt;
&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;#39;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp, Ubuntu:25.10: isc-dhcp, Ubuntu:26.04:LTS: isc-dhcp&lt;/p&gt;
&lt;p&gt;Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver&amp;#39;s CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12705</guid>
    </item>
    <item>
      <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-053</link>
      <description>&lt;p&gt;Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-053</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0217 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0217</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0217</guid>
    </item>
  </channel>
</rss>
