ISC has released BIND 9.20.29, 9.21.26, and BIND Supported Preview Edition 9.20.29-S1 to fix 14 denial-of-service flaws, including seven rated high. One of the crashes needs only a crafted DNS-over-HTTPS request and no credentials: ISC says a bad SIG(0) signature and a closed connection can make named abort.
The mechanism is a service crash, not code execution. In the DoH case, the server starts checking the signature and dies if the sender drops the connection before that check finishes; other flaws can drain memory or CPU, or terminate the resolver under crafted DNS traffic.
The catch is the packaging gap: ISC ended support for 9.18 and shipped no 9.18 fix, yet some operating-system packages still carry 9.18 builds. For DNS operators and distro maintainers, the exposure now sits with downstream packaging as much as with ISC itself.
ISC ha rilasciato aggiornamenti di sicurezza per BIND 9 e BIND Supported Preview Edition, software per la gestione e la risoluzione delle richieste DNS, che sanano alcune vulnerabilità, di cui 7 con gravità "alta".