Known issues in this release
-
-
diff --git a/RELEASE-NOTES-BIND-9.7.4.pdf b/RELEASE-NOTES-BIND-9.7.4.pdf
index 94edfcf6a5..1082b592e1 100644
Binary files a/RELEASE-NOTES-BIND-9.7.4.pdf and b/RELEASE-NOTES-BIND-9.7.4.pdf differ
diff --git a/RELEASE-NOTES-BIND-9.7.4.txt b/RELEASE-NOTES-BIND-9.7.4.txt
index ae736f44e5..6dd7e69e79 100644
--- a/RELEASE-NOTES-BIND-9.7.4.txt
+++ b/RELEASE-NOTES-BIND-9.7.4.txt
@@ -2,11 +2,11 @@
Introduction
- BIND 9.7.4rc1 is the first release candidate of BIND 9.7.4.
+ BIND 9.7.4 is the current production release of BIND 9.7.
- This document summarizes changes from BIND 9.7.3 to BIND 9.7.4rc1.
- Please see the CHANGES file in the source code release for a complete
- list of all changes.
+ This document summarizes changes from BIND 9.7.3 to BIND 9.7.4. Please
+ see the CHANGES file in the source code release for a complete list of
+ all changes.
Download
@@ -25,16 +25,29 @@ Support
New Features
-9.7.4rc1
+9.7.4
* A new test has been added to check the apex NSEC3 records after
DNSKEY records have been added via dynamic update. [RT #23229]
* Added a tool able to generate malformed packets to allow testing of
how named handles them. [RT #24096]
+Security Fixes
+
+9.7.4
+
+ * named, set up to be a caching resolver, is vulnerable to a user
+ querying a domain with very large resource record sets (RRSets)
+ when trying to negatively cache the response. Due to an off-by-one
+ error, caching the response could cause named to crash. [RT #24650]
+ [CVE-2011-1910]
+ * Change #2912 (see CHANGES) exposed a latent bug in the DNS message
+ processing code that could allow certain UPDATE requests to crash
+ named. [RT #24777] [CVE-2011-2464]
+
Feature Changes
-9.7.4rc1
+9.7.4
* Merged in the NetBSD ATF test framework (currently version 0.12)
for development of future unit tests. Use configure --with-atf to
@@ -43,39 +56,23 @@ Feature Changes
* Added more verbose error reporting from DLZ LDAP. [RT #23402]
* Replaced compile time constant with STDTIME_ON_32BITS. [RT #23587]
-Security Fixes
-
-9.7.4rc1
-
- * Change #2912 (see CHANGES) exposed a latent bug in the DNS message
- processing code that could allow certain UPDATE requests to crash
- named. [RT #24777] [CVE-2011-2464]
- * named, set up to be a caching resolver, is vulnerable to a user
- querying a domain with very large resource record sets (RRSets)
- when trying to negatively cache the response. Due to an off-by-one
- error, caching the response could cause named to crash. [RT #24650]
- [CVE-2011-1910]
-
Bug Fixes
-9.7.4rc1
+9.7.4
- * Improved the mechanism for flagging database entries as negative
- cache records; the former method, RR type 0, could be ambiguous.
- [RT #24777]
* During RFC5011 processing some journal write errors were not
detected. This could lead to managed-keys changes being committed
but not recorded in the journal files, causing potential
inconsistencies during later processing. [RT #20256]
- * A potential NULL pointer deference in the DNS64 code could cause
+ A potential NULL pointer deference in the DNS64 code could cause
named to terminate unexpectedly. [RT #20256]
- * A state variable relating to DNSSEC could fail to be set during
+ A state variable relating to DNSSEC could fail to be set during
some infrequently-executed code paths, allowing it to be used
whilst in an unitialized state during cache updates, with
unpredictable results. [RT #20256]
- * A potential NULL pointer deference in DNSSEC signing code could
+ A potential NULL pointer deference in DNSSEC signing code could
cause named to terminate unexpectedly [RT #20256]
- * Several cosmetic code changes were made to silence warnings
+ Several cosmetic code changes were made to silence warnings
generated by a static code analysis tool. [RT #20256]
* When using the -x (sign with only KSK) option on dnssec-signzone,
it could incorrectly count the number of ZSKs in the zone. (And in
@@ -84,7 +81,6 @@ Bug Fixes
* When using _builtin in named.conf, named.conf changes were not
found when reloading the config file. Now checks _builtin zone
arguments to see if the zone is re-usable or not. [RT #21914]
- * After an external code review, a code cleanup was done. [RT #22521]
* After an "rndc reconfig", the refresh timer for managed-keys is
ignored, resulting in managed-keys not being refreshed until named
is restarted. [RT #22296]
@@ -92,6 +88,7 @@ Bug Fixes
key to be rewritten to the new key format even if no other change
has been specified, using "-P now -A now" as default values. [RT
#22474]
+ * After an external code review, a code cleanup was done. [RT #22521]
* Cause named to terminate at startup or rndc reconfig reload to
fail, if a log file specified in the conf file isn't a plain file.
(RT #22771]
@@ -117,6 +114,9 @@ Bug Fixes
private key is found. [RT #23136]
* When using auto-dnssec and updating DNSKEY records, named did
correctly update the zone. [RT #23232]
+ * When using "auto-dnssec maintain" and rolling to a new key, a
+ private-type record (only used internally by named) could be
+ created and not marked as complete. [RT #23253]
* If a slave initiates a TSIG signed AXFR from the master and the
master fails to correctly TSIG sign the final message, the slave
would be left with the zone in an unclean state. named detected
@@ -184,6 +184,8 @@ Bug Fixes
incorrect timer setting. [RT #23769]
* The autosign tests attempted to open ports within reserved ranges.
Test now avoids those ports. [RT #23957]
+ * named, acting as authoritative server for DLZ zones, was not
+ correctly setting the authoritative (AA) bit. [RT #24146]
* Clean up some cross-compiling issues and added two undocumented
configure options, --with-gost and --with-rlimtype, to allow
over-riding default settings (gost=no and rlimtype="long int") when
@@ -195,11 +197,25 @@ Bug Fixes
* Improved consistency checks for dnssec-enable and
dnssec-validation, added test cases to the checkconf system test.
[RT #24398]
+ * RT #23136 fixed a problem where named would delete old signatures
+ even when the private key wasn't available to re-sign the zone,
+ resulting in a zone with missing signatures. This fix (CHANGES
+ 3114) did not completely fix all issues. [RT #24577]
* nsupdate could dump core on shutdown when using SIG(0) keys. [RT
#24604]
* Named could fail to validate zones list in a DLV that validated
insecure without using DLV and had DS records in the parent zone.
[RT #24631]
+ * A bug in FreeBSD kernels causes IPv6 UDP responses greater than
+ 1280 bytes to not fragment as they should. Until there is a kernel
+ fix, named will work around this by setting IPV6_USE_MIN_MTU on a
+ per packet basis. [RT #24950]
+ * To avoid excessive startup time for configurations with large
+ numbers of zones, an environment variable, BIND9_ZONE_TASKS_HINTS,
+ may now be set prior to starting named. Divide your number of zones
+ by 200 to find the recommended setting for this environment
+ variable (i.e., if you have 200000 zones, set
+ BIND9_ZONE_TASKS_HINTS to 1000 before starting named). [RT #25084]
Known issues in this release