diff --git a/CHANGES b/CHANGES index 36db530137..cef13738f4 100644 --- a/CHANGES +++ b/CHANGES @@ -5,6 +5,8 @@ configuration included the "tkey-gssapi-credential" option. This has been fixed. [GL #2634] + --- 9.11.30 released --- + 5617. [security] A specially crafted GSS-TSIG query could cause a buffer overflow in the ISC implementation of SPNEGO. (CVE-2021-25216) [GL #2604] diff --git a/README b/README index bd12f96cec..bf2eef7817 100644 --- a/README +++ b/README @@ -377,6 +377,12 @@ BIND 9.11.29 BIND 9.11.29 is a maintenance release. +BIND 9.11.30 + +BIND 9.11.30 is a maintenance release, and also addresses the security +vulnerabilities disclosed in CVE-2021-25214, CVE-2021-25215, and +CVE-2021-25216. + Building BIND Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler, diff --git a/README.md b/README.md index 6ecb9b3b73..201124153e 100644 --- a/README.md +++ b/README.md @@ -394,6 +394,12 @@ vulnerability disclosed in CVE-2020-8625. BIND 9.11.29 is a maintenance release. +#### BIND 9.11.30 + +BIND 9.11.30 is a maintenance release, and also addresses the security +vulnerabilities disclosed in CVE-2021-25214, CVE-2021-25215, and +CVE-2021-25216. + ### Building BIND Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler, diff --git a/configure b/configure index ce5a1dca9d..5e68976c6f 100755 --- a/configure +++ b/configure @@ -978,7 +978,6 @@ infodir docdir oldincludedir includedir -runstatedir localstatedir sharedstatedir sysconfdir @@ -1152,7 +1151,6 @@ datadir='${datarootdir}' sysconfdir='${prefix}/etc' sharedstatedir='${prefix}/com' localstatedir='${prefix}/var' -runstatedir='${localstatedir}/run' includedir='${prefix}/include' oldincludedir='/usr/include' docdir='${datarootdir}/doc/${PACKAGE_TARNAME}' @@ -1405,15 +1403,6 @@ do | -silent | --silent | --silen | --sile | --sil) silent=yes ;; - -runstatedir | --runstatedir | --runstatedi | --runstated \ - | --runstate | --runstat | --runsta | --runst | --runs \ - | --run | --ru | --r) - ac_prev=runstatedir ;; - -runstatedir=* | --runstatedir=* | --runstatedi=* | --runstated=* \ - | --runstate=* | --runstat=* | --runsta=* | --runst=* | --runs=* \ - | --run=* | --ru=* | --r=*) - runstatedir=$ac_optarg ;; - -sbindir | --sbindir | --sbindi | --sbind | --sbin | --sbi | --sb) ac_prev=sbindir ;; -sbindir=* | --sbindir=* | --sbindi=* | --sbind=* | --sbin=* \ @@ -1551,7 +1540,7 @@ fi for ac_var in exec_prefix prefix bindir sbindir libexecdir datarootdir \ datadir sysconfdir sharedstatedir localstatedir includedir \ oldincludedir docdir infodir htmldir dvidir pdfdir psdir \ - libdir localedir mandir runstatedir + libdir localedir mandir do eval ac_val=\$$ac_var # Remove trailing slashes. @@ -1704,7 +1693,6 @@ Fine tuning of the installation directories: --sysconfdir=DIR read-only single-machine data [PREFIX/etc] --sharedstatedir=DIR modifiable architecture-independent data [PREFIX/com] --localstatedir=DIR modifiable single-machine data [PREFIX/var] - --runstatedir=DIR modifiable per-process data [LOCALSTATEDIR/run] --libdir=DIR object code libraries [EPREFIX/lib] --includedir=DIR C header files [PREFIX/include] --oldincludedir=DIR C header files for non-gcc [/usr/include] diff --git a/doc/arm/Bv9ARM.ch01.html b/doc/arm/Bv9ARM.ch01.html index 297269af6f..baf9e036bd 100644 --- a/doc/arm/Bv9ARM.ch01.html +++ b/doc/arm/Bv9ARM.ch01.html @@ -576,6 +576,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch02.html b/doc/arm/Bv9ARM.ch02.html index af2cce96e0..674e15c408 100644 --- a/doc/arm/Bv9ARM.ch02.html +++ b/doc/arm/Bv9ARM.ch02.html @@ -144,6 +144,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch03.html b/doc/arm/Bv9ARM.ch03.html index 2d83e5515a..94eb812f52 100644 --- a/doc/arm/Bv9ARM.ch03.html +++ b/doc/arm/Bv9ARM.ch03.html @@ -654,6 +654,6 @@ controls { -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch04.html b/doc/arm/Bv9ARM.ch04.html index d72442c6a2..9016b8d582 100644 --- a/doc/arm/Bv9ARM.ch04.html +++ b/doc/arm/Bv9ARM.ch04.html @@ -2664,6 +2664,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch05.html b/doc/arm/Bv9ARM.ch05.html index 5d9930e588..efb6fcf46a 100644 --- a/doc/arm/Bv9ARM.ch05.html +++ b/doc/arm/Bv9ARM.ch05.html @@ -131,6 +131,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 71159d1733..beeb7ea810 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -12842,6 +12842,6 @@ HOST-127.EXAMPLE. MX 0 . -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index 2d74cbba35..861895d205 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -384,6 +384,6 @@ allow-query { !{ !10/8; any; }; key example; }; -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index be4f81d5ff..2f4ae0f4b2 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -125,6 +125,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index 5d2b864303..c3be5e80ed 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -36,11 +36,12 @@

Table of Contents

-
Release Notes for BIND Version 9.11.29
+
Release Notes for BIND Version 9.11.30
Introduction
Download
License Change
+
Notes for BIND 9.11.30
Notes for BIND 9.11.29
Notes for BIND 9.11.28
Notes for BIND 9.11.27
@@ -78,7 +79,7 @@

-Release Notes for BIND Version 9.11.29

+Release Notes for BIND Version 9.11.30

Introduction

@@ -134,6 +135,66 @@

+Notes for BIND 9.11.30

+
+

+Security Fixes

+
    +
  • +

    + A malformed incoming IXFR transfer could trigger an assertion failure + in named, causing it to quit abnormally. + (CVE-2021-25214) +

    +

    + ISC would like to thank Greg Kuechle of SaskTel for bringing this + vulnerability to our attention. [GL #2467] +

    +
  • +
  • +

    + named crashed when a DNAME record placed in the + ANSWER section during DNAME chasing turned out to be the final answer + to a client query. (CVE-2021-25215) +

    +

    + ISC would like to thank Siva Kakarla for + bringing this vulnerability to our attention. [GL #2540] +

    +
  • +
  • +

    + When a server's configuration set the + tkey-gssapi-keytab or + tkey-gssapi-credential option, a specially crafted + GSS-TSIG query could cause a buffer overflow in the ISC implementation + of SPNEGO (a protocol enabling negotiation of the security mechanism + used for GSSAPI authentication). This flaw could be exploited to crash + named binaries compiled for 64-bit platforms, and + could enable remote code execution when named was + compiled for 32-bit platforms. (CVE-2021-25216) +

    +

    + This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro + Zero Day Initiative. [GL #2604] +

    +
  • +
+
+
+

+Feature Changes

+
  • + The ISC implementation of SPNEGO was removed from BIND 9 source code. + Instead, BIND 9 now always uses the SPNEGO implementation provided by + the system GSSAPI library when it is built with GSSAPI support. All + major contemporary Kerberos/GSSAPI libraries contain an implementation + of the SPNEGO mechanism. [GL #2607] +

+
+
+
+

Notes for BIND 9.11.29

@@ -2134,6 +2195,6 @@

-

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch10.html b/doc/arm/Bv9ARM.ch10.html index 1a83baabc7..fa6e8b86a3 100644 --- a/doc/arm/Bv9ARM.ch10.html +++ b/doc/arm/Bv9ARM.ch10.html @@ -148,6 +148,6 @@
-

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch11.html b/doc/arm/Bv9ARM.ch11.html index 297ffeee1b..605dc65bd7 100644 --- a/doc/arm/Bv9ARM.ch11.html +++ b/doc/arm/Bv9ARM.ch11.html @@ -508,6 +508,6 @@
-

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch12.html b/doc/arm/Bv9ARM.ch12.html index 0a3d7347d0..8945031a49 100644 --- a/doc/arm/Bv9ARM.ch12.html +++ b/doc/arm/Bv9ARM.ch12.html @@ -473,6 +473,6 @@ $ sample-update -a sample-update -k Kxxx.+nnn+mm
-

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch13.html b/doc/arm/Bv9ARM.ch13.html index c3079b345d..46d93717a6 100644 --- a/doc/arm/Bv9ARM.ch13.html +++ b/doc/arm/Bv9ARM.ch13.html @@ -176,6 +176,6 @@
-

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.html b/doc/arm/Bv9ARM.html index bf2f7992f8..c17434a0b1 100644 --- a/doc/arm/Bv9ARM.html +++ b/doc/arm/Bv9ARM.html @@ -32,7 +32,7 @@

BIND 9 Administrator Reference Manual

-

BIND Version 9.11.29

+

BIND Version 9.11.30


@@ -241,11 +241,12 @@
A. Release Notes
-
Release Notes for BIND Version 9.11.29
+
Release Notes for BIND Version 9.11.30
Introduction
Download
License Change
+
Notes for BIND 9.11.30
Notes for BIND 9.11.29
Notes for BIND 9.11.28
Notes for BIND 9.11.27
@@ -440,6 +441,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.pdf b/doc/arm/Bv9ARM.pdf index b70e1aed1a..a46b1d63f0 100644 Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ diff --git a/doc/arm/man.arpaname.html b/doc/arm/man.arpaname.html index f1b76abd41..782b98c15a 100644 --- a/doc/arm/man.arpaname.html +++ b/doc/arm/man.arpaname.html @@ -72,6 +72,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.ddns-confgen.html b/doc/arm/man.ddns-confgen.html index a6ca0f2bf6..7e7bbe1199 100644 --- a/doc/arm/man.ddns-confgen.html +++ b/doc/arm/man.ddns-confgen.html @@ -176,6 +176,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.delv.html b/doc/arm/man.delv.html index 17f9b4b341..ac575f2109 100644 --- a/doc/arm/man.delv.html +++ b/doc/arm/man.delv.html @@ -499,6 +499,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 24118057ba..2207c2e1c0 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -919,6 +919,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-checkds.html b/doc/arm/man.dnssec-checkds.html index ef802f988d..a3b9b90e92 100644 --- a/doc/arm/man.dnssec-checkds.html +++ b/doc/arm/man.dnssec-checkds.html @@ -101,6 +101,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-coverage.html b/doc/arm/man.dnssec-coverage.html index d162c59c51..c29b101fc0 100644 --- a/doc/arm/man.dnssec-coverage.html +++ b/doc/arm/man.dnssec-coverage.html @@ -221,6 +221,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-dsfromkey.html b/doc/arm/man.dnssec-dsfromkey.html index 3f494aafcd..503d667329 100644 --- a/doc/arm/man.dnssec-dsfromkey.html +++ b/doc/arm/man.dnssec-dsfromkey.html @@ -239,6 +239,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-importkey.html b/doc/arm/man.dnssec-importkey.html index 79d8e46fa3..e10fda6c59 100644 --- a/doc/arm/man.dnssec-importkey.html +++ b/doc/arm/man.dnssec-importkey.html @@ -179,6 +179,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index 1e0e1fff25..2cac5ecf9f 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -381,6 +381,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 2d0c44b9e6..db9703745d 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -462,6 +462,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-keymgr.html b/doc/arm/man.dnssec-keymgr.html index bfbd8c5d98..49f8365767 100644 --- a/doc/arm/man.dnssec-keymgr.html +++ b/doc/arm/man.dnssec-keymgr.html @@ -328,6 +328,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-revoke.html b/doc/arm/man.dnssec-revoke.html index ad045a05f9..f713424398 100644 --- a/doc/arm/man.dnssec-revoke.html +++ b/doc/arm/man.dnssec-revoke.html @@ -126,6 +126,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-settime.html b/doc/arm/man.dnssec-settime.html index e712d08de4..7777c518a9 100644 --- a/doc/arm/man.dnssec-settime.html +++ b/doc/arm/man.dnssec-settime.html @@ -269,6 +269,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index da683e4b3a..fc6d5a6344 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -559,6 +559,6 @@ db.example.com.signed -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-verify.html b/doc/arm/man.dnssec-verify.html index 8e29d2639c..8a17131a21 100644 --- a/doc/arm/man.dnssec-verify.html +++ b/doc/arm/man.dnssec-verify.html @@ -156,6 +156,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.dnstap-read.html b/doc/arm/man.dnstap-read.html index b66a96ad27..6e473e206c 100644 --- a/doc/arm/man.dnstap-read.html +++ b/doc/arm/man.dnstap-read.html @@ -99,6 +99,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.genrandom.html b/doc/arm/man.genrandom.html index 820063c3b2..956fe087e3 100644 --- a/doc/arm/man.genrandom.html +++ b/doc/arm/man.genrandom.html @@ -93,6 +93,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 003a51bbda..38bd135f79 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -292,6 +292,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.isc-hmac-fixup.html b/doc/arm/man.isc-hmac-fixup.html index 6dfdf67314..72a132e020 100644 --- a/doc/arm/man.isc-hmac-fixup.html +++ b/doc/arm/man.isc-hmac-fixup.html @@ -103,6 +103,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.lwresd.html b/doc/arm/man.lwresd.html index 6a6bd34e93..722c4471d1 100644 --- a/doc/arm/man.lwresd.html +++ b/doc/arm/man.lwresd.html @@ -245,6 +245,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.mdig.html b/doc/arm/man.mdig.html index 1e8eb96131..95c74f7d28 100644 --- a/doc/arm/man.mdig.html +++ b/doc/arm/man.mdig.html @@ -472,6 +472,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index bfe101c62e..9f4ae31040 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -146,6 +146,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index 6481c190af..0a45ad9ccb 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -330,6 +330,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named-journalprint.html b/doc/arm/man.named-journalprint.html index 02c19cc452..99c3a03f51 100644 --- a/doc/arm/man.named-journalprint.html +++ b/doc/arm/man.named-journalprint.html @@ -94,6 +94,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named-nzd2nzf.html b/doc/arm/man.named-nzd2nzf.html index 5be2d85b01..7912aefb9c 100644 --- a/doc/arm/man.named-nzd2nzf.html +++ b/doc/arm/man.named-nzd2nzf.html @@ -95,6 +95,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named-rrchecker.html b/doc/arm/man.named-rrchecker.html index e94f738ffa..580109688f 100644 --- a/doc/arm/man.named-rrchecker.html +++ b/doc/arm/man.named-rrchecker.html @@ -96,6 +96,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named.conf.html b/doc/arm/man.named.conf.html index 4de64b3bf0..e376835854 100644 --- a/doc/arm/man.named.conf.html +++ b/doc/arm/man.named.conf.html @@ -974,6 +974,6 @@ zone -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index ac93282c0b..deeb49a112 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -376,6 +376,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.nsec3hash.html b/doc/arm/man.nsec3hash.html index 72179c6393..0960006b2d 100644 --- a/doc/arm/man.nsec3hash.html +++ b/doc/arm/man.nsec3hash.html @@ -98,6 +98,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.nslookup.html b/doc/arm/man.nslookup.html index 77b4e81428..8a09cf4a47 100644 --- a/doc/arm/man.nslookup.html +++ b/doc/arm/man.nslookup.html @@ -362,6 +362,6 @@ nslookup -query=hinfo -timeout=10 -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.nsupdate.html b/doc/arm/man.nsupdate.html index 7c52e46e3c..b6da68d703 100644 --- a/doc/arm/man.nsupdate.html +++ b/doc/arm/man.nsupdate.html @@ -671,6 +671,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-destroy.html b/doc/arm/man.pkcs11-destroy.html index 11a215ce8d..53b8c7cfa7 100644 --- a/doc/arm/man.pkcs11-destroy.html +++ b/doc/arm/man.pkcs11-destroy.html @@ -116,6 +116,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-keygen.html b/doc/arm/man.pkcs11-keygen.html index 91cd25b019..38a6c4c1aa 100644 --- a/doc/arm/man.pkcs11-keygen.html +++ b/doc/arm/man.pkcs11-keygen.html @@ -141,6 +141,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-list.html b/doc/arm/man.pkcs11-list.html index f204f9b62f..d9f6c90abb 100644 --- a/doc/arm/man.pkcs11-list.html +++ b/doc/arm/man.pkcs11-list.html @@ -114,6 +114,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-tokens.html b/doc/arm/man.pkcs11-tokens.html index 83bbdd81f3..789b5a9c2a 100644 --- a/doc/arm/man.pkcs11-tokens.html +++ b/doc/arm/man.pkcs11-tokens.html @@ -91,6 +91,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 28d28ff4ee..e62c54dc24 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -216,6 +216,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index e2f7d7f95c..c2427ef5be 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -238,6 +238,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index 899ac2dd57..776ae85ea6 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -786,6 +786,6 @@ -

BIND 9.11.29 (Extended Support Version)

+

BIND 9.11.30 (Extended Support Version)

diff --git a/doc/arm/notes.html b/doc/arm/notes.html index e2f0a54f5d..bc1dcbe782 100644 --- a/doc/arm/notes.html +++ b/doc/arm/notes.html @@ -13,7 +13,7 @@

-Release Notes for BIND Version 9.11.29

+Release Notes for BIND Version 9.11.30

Introduction

@@ -69,6 +69,66 @@

+Notes for BIND 9.11.30

+
+

+Security Fixes

+
    +
  • +

    + A malformed incoming IXFR transfer could trigger an assertion failure + in named, causing it to quit abnormally. + (CVE-2021-25214) +

    +

    + ISC would like to thank Greg Kuechle of SaskTel for bringing this + vulnerability to our attention. [GL #2467] +

    +
  • +
  • +

    + named crashed when a DNAME record placed in the + ANSWER section during DNAME chasing turned out to be the final answer + to a client query. (CVE-2021-25215) +

    +

    + ISC would like to thank Siva Kakarla for + bringing this vulnerability to our attention. [GL #2540] +

    +
  • +
  • +

    + When a server's configuration set the + tkey-gssapi-keytab or + tkey-gssapi-credential option, a specially crafted + GSS-TSIG query could cause a buffer overflow in the ISC implementation + of SPNEGO (a protocol enabling negotiation of the security mechanism + used for GSSAPI authentication). This flaw could be exploited to crash + named binaries compiled for 64-bit platforms, and + could enable remote code execution when named was + compiled for 32-bit platforms. (CVE-2021-25216) +

    +

    + This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro + Zero Day Initiative. [GL #2604] +

    +
  • +
+
+
+

+Feature Changes

+
  • + The ISC implementation of SPNEGO was removed from BIND 9 source code. + Instead, BIND 9 now always uses the SPNEGO implementation provided by + the system GSSAPI library when it is built with GSSAPI support. All + major contemporary Kerberos/GSSAPI libraries contain an implementation + of the SPNEGO mechanism. [GL #2607] +

+
+
+
+

Notes for BIND 9.11.29

diff --git a/doc/arm/notes.pdf b/doc/arm/notes.pdf index 77f16d327a..a6f549f499 100644 Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ diff --git a/doc/arm/notes.txt b/doc/arm/notes.txt index c67f18a17d..c75771b09d 100644 --- a/doc/arm/notes.txt +++ b/doc/arm/notes.txt @@ -1,4 +1,4 @@ -Release Notes for BIND Version 9.11.29 +Release Notes for BIND Version 9.11.30 Introduction @@ -36,6 +36,43 @@ Those unsure whether or not the license change affects their use of BIND, or who wish to discuss how to comply with the license may contact ISC at https://www.isc.org/mission/contact/. +Notes for BIND 9.11.30 + +Security Fixes + + • A malformed incoming IXFR transfer could trigger an assertion failure + in named, causing it to quit abnormally. (CVE-2021-25214) + + ISC would like to thank Greg Kuechle of SaskTel for bringing this + vulnerability to our attention. [GL #2467] + + • named crashed when a DNAME record placed in the ANSWER section during + DNAME chasing turned out to be the final answer to a client query. + (CVE-2021-25215) + + ISC would like to thank Siva Kakarla for bringing this vulnerability + to our attention. [GL #2540] + + • When a server's configuration set the tkey-gssapi-keytab or + tkey-gssapi-credential option, a specially crafted GSS-TSIG query + could cause a buffer overflow in the ISC implementation of SPNEGO (a + protocol enabling negotiation of the security mechanism used for + GSSAPI authentication). This flaw could be exploited to crash named + binaries compiled for 64-bit platforms, and could enable remote code + execution when named was compiled for 32-bit platforms. + (CVE-2021-25216) + + This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro + Zero Day Initiative. [GL #2604] + +Feature Changes + + • The ISC implementation of SPNEGO was removed from BIND 9 source code. + Instead, BIND 9 now always uses the SPNEGO implementation provided by + the system GSSAPI library when it is built with GSSAPI support. All + major contemporary Kerberos/GSSAPI libraries contain an implementation + of the SPNEGO mechanism. [GL #2607] + Notes for BIND 9.11.29 Bug Fixes diff --git a/lib/dns/api b/lib/dns/api index 9112a5f218..0418fc842f 100644 --- a/lib/dns/api +++ b/lib/dns/api @@ -8,6 +8,6 @@ # 9.10-sub: 180-189 # 9.11: 160-169,1100-1199 # 9.12: 1200-1299 -LIBINTERFACE = 1113 -LIBREVISION = 2 +LIBINTERFACE = 1114 +LIBREVISION = 0 LIBAGE = 0 diff --git a/version b/version index a4f4f7a2ca..9ec5dc8899 100644 --- a/version +++ b/version @@ -5,7 +5,7 @@ PRODUCT=BIND DESCRIPTION="(Extended Support Version)" MAJORVER=9 MINORVER=11 -PATCHVER=29 +PATCHVER=30 RELEASETYPE= RELEASEVER= EXTENSIONS=