Debian 11030 Published by

Debian published multiple security advisories to patch critical flaws across PowerDNS, Nginx, Chromium, and Bind9. The updates resolve CVE-2026-52682 in pdns-recursor, pdns, and dnsdist, which could trigger denial of service attacks through malformed DNS packets. The advisory also covers Nginx, which requires updates to patch proxy and charset module flaws, alongside Chromium, which addresses forty-one distinct vulnerabilities that could enable arbitrary code execution or memory disclosure. Bind9 receives the most extensive corrections, sealing flaws that previously enabled cache poisoning, DNSSEC validation bypass, and unbounded memory consumption.

[DSA 6421-1] pdns-recursor security update
[DSA 6420-1] pdns security update
[DSA 6419-1] dnsdist security update
ELA-1797-1 nginx security update (by )
[DSA 6422-1] chromium security update
[DLA 4725-1] bind9 security update




[SECURITY] [DSA 6421-1] pdns-recursor security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6421-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 08, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : pdns-recursor
CVE ID : CVE-2026-52682

A vulnerability was discovered in PowerDNS Recursor ("pdns-recursor"), a
resolving name server, which may result in denial of service (increased
memory and CPU usage) when processing a specially crafted DNS packet.

For the stable distribution (trixie), this problem has been fixed in
version 5.2.13-0+deb13u1.

We recommend that you upgrade your pdns-recursor packages.

For the detailed security status of pdns-recursor please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/pdns-recursor

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6420-1] pdns security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6420-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 08, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : pdns
CVE ID : CVE-2026-52682

A vulnerability was discovered in PowerDNS Authoritative server
("pdns"), which may result in denial of service (increased memory and
CPU usage) when processing a specially crafted DNS packet.

For the stable distribution (trixie), this problem has been fixed in
version 4.9.17-0+deb13u1.

We recommend that you upgrade your pdns packages.

For the detailed security status of pdns please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/pdns

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6419-1] dnsdist security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6419-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 08, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : dnsdist
CVE ID : CVE-2026-52682

A vulnerability was discovered in the dnsdist DNS loadbalancer, which
may result in denial of service (increased memory and CPU usage) when
processing a specially crafted DNS packet.

For the stable distribution (trixie), this problem has been fixed in
version 1.9.16-0+deb13u1.

We recommend that you upgrade your dnsdist packages.

For the detailed security status of dnsdist please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/dnsdist

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1797-1 nginx security update (by )


Package : nginx

Version : 1.14.2-2+deb10u8 (buster)

Related CVEs :
CVE-2026-42055
CVE-2026-48142

Multiple vulnerabilities were discoverd in Nginx, a high-performance web
and reverse proxy server, which could result in remote code execution,
denial of service or memory disclosure.

CVE-2026-42055

NGINX Open Source has a vulnerability in the ngx_http_proxy_v2_module and
ngx_http_grpc_module modules. This vulnerability exists when the
proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2
traffic, the ignore_invalid_headers directive is set to off, and the
large_client_header_buffers directive size is larger than 2 megabytes. A
remote, unauthenticated attacker, along with conditions beyond their
control, could send large headers while creating an upstream request. This
may cause a heap-based buffer overflow in the NGINX worker process leading
to a restart. Additionally, attackers can execute code on systems with
Address Space Layout Randomization (ASLR) disabled or when the attacker can
bypass ASLR.

CVE-2026-48142

NGINX Open Source has a vulnerability in the ngx_http_charset_module module.
When content is served or proxied through a location block with both
source_charset utf-8; and a charset directive (for example, charset koi8-r;)
configured, remote, unauthenticated attackers can send requests (in
conjunction with conditions beyond their control) to cause a heap buffer
over-read in the NGINX worker process, leading to limited disclosure of
memory or a restart.

No CVE assigned yet

HTTP/2 Bomb denial of service.


ELA-1797-1 nginx security update (by )



[SECURITY] [DSA 6422-1] chromium security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6422-1 security@debian.org
https://www.debian.org/security/ Andres Salomon
August 08, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium
CVE ID : CVE-2026-19137 CVE-2026-19138 CVE-2026-19139 CVE-2026-19140
CVE-2026-19141 CVE-2026-19142 CVE-2026-19143 CVE-2026-19144
CVE-2026-19145 CVE-2026-19146 CVE-2026-19147 CVE-2026-19148
CVE-2026-19149 CVE-2026-19150 CVE-2026-19151 CVE-2026-19152
CVE-2026-19153 CVE-2026-19154 CVE-2026-19155 CVE-2026-19156
CVE-2026-19157 CVE-2026-19158 CVE-2026-19159 CVE-2026-19160
CVE-2026-19161 CVE-2026-19162 CVE-2026-19163 CVE-2026-19164
CVE-2026-19165 CVE-2026-19166 CVE-2026-19167 CVE-2026-19168
CVE-2026-19169 CVE-2026-19170 CVE-2026-19171 CVE-2026-19172
CVE-2026-19173 CVE-2026-19174 CVE-2026-19175 CVE-2026-19176
CVE-2026-19177

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For the stable distribution (trixie), these problems have been fixed in
version 151.0.7922.108-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4725-1] bind9 security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4725-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emmanuel Arias
August 08, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : bind9
Version : 1:9.16.50-1~deb11u6 1:9.18.49-1~deb12u2
CVE ID : CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950
CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605
CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204
CVE-2026-13321

Several vulnerabilities were found in bind9, a DNS server implementation, which
may lead to denial of service, DNSSEC validation bypass, cache poisoning or RPZ
policy bypass.

CVE-2026-3039

Servers configured for TKEY authentication using GSS-API tokens can be
driven into unbounded memory growth while parsing specially crafted packets.
Such setups are common in Active Directory integrated DNS deployments and in
Kerberos-secured DNS environments.

CVE-2026-3592

A resolver querying a specially crafted zone ends up doing far more work
than the original query would justify, which an attacker can abuse as an
amplified resource exhaustion vector.

CVE-2026-5946

A group of related defects was found in the way named processes DNS messages
carrying a CLASS other than Internet (IN), as well as messages using the
meta-classes ANY or NONE in the question section.

CVE-2026-5950

While handling misbehaving servers, the resolver state machine could enter a
resend loop with no upper bound. A remote, unauthenticated attacker able to
trigger those retry conditions can exhaust the service's resources.

CVE-2026-10723

The signer name of NSEC3 records was not checked correctly, so named could
treat bogus child-zone NSEC3 records as legitimate. This opened the door to
forged NXDOMAIN answers that appear authenticated.

CVE-2026-10822

A malformed DNSKEY record could reach an assertion. When BIND ran into such
an invalid data structure it accepted it and stored the bogus identifier,
and could later abort and terminate.

CVE-2026-11331

RPZ processing of wildcard CNAME policies could produce a name exceeding the
maximum length. An attacker aware (or merely suspecting) that a resolver
applies such policies can craft query names long enough to hit the resulting
NAMETOOLONG error condition.

CVE-2026-11605

A validating resolver could be made to spend a disproportionate amount of
CPU time on DNSSEC validation for a single answer, verifying signatures that
were never needed. A malicious authoritative server returning unsolicited or
superfluous RRSIG records is enough to trigger it.

CVE-2026-11622

A DNSSEC-validating resolver targeted by a random subdomain attack against a
signed zone could keep growing its memory footprint without bound,
exhausting the cache.

CVE-2026-11721

An attacker-controlled zone could answer with an RRSIG whose label count is
lower than that of the zone holding it. Such invalid signed wildcard records
are no longer accepted.

CVE-2026-12617

Depending on the ordering and the exact contents of the answers returned for
CNAME or DNAME queries together with A records, named could reach an
assertion and terminate unexpectedly.

CVE-2026-13204

When a provably insecure domain is covered at the parent by both an NSEC
and an NSEC3 record but only one of the two types carries an RRSIG,
validating that proof could make BIND hit an assertion and exit.

CVE-2026-13321

The resolver accepted properly signed NSEC records whose 'Next Domain
Name' field points outside the signer's zone, which could be used to
bypass DNSSEC validation.

For Debian 11 bullseye, these problems have been fixed in version
1:9.16.50-1~deb11u6.

For Debian 12 bookworm, these problems have been fixed in version
1:9.18.49-1~deb12u2.

We recommend that you upgrade your bind9 packages.

For the detailed security status of bind9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/bind9

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS