<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ISC Knowledgebase</title>
    <description />
    <link>https://kb.isc.org/docs</link>
    <atom:link href="https://kb.isc.org/rss/en" rel="self" type="application/rss+xml" />
    <item>
      <title>Security Matrices for Obsolete BIND Branches</title>
      <description>The vulnerability matrix for each obsolete branch of BIND is kept available for historical reference.  For currently supported releases, see the BIND 9 Software Vulnerability Matrix instead.
SECURITY WARNING

Obsolete versions of BIND are all known to be vulnerable.  ISC strongly recommends upgrading to a current version as soon as practical.
The obsolete matrices will not be updated to reflect new vulnerabilities.  You must assume you are vulnerable if you are running an obsolete version.

For  ...</description>
      <pubDate>Sat, 30 May 2026 18:07:18 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; Obsolete Matrices</category>
      <link>https://kb.isc.org/docs/obsolete-bind-vulnerability-lists</link>
      <guid>https://kb.isc.org/docs/obsolete-bind-vulnerability-lists</guid>
    </item>
    <item>
      <title>A Note About BIND Release Notes</title>
      <description>If you are looking for the release notes for the current versions of BIND, please visit the following URL, and then select the directory for the major branch you are running:
https://downloads.isc.org/isc/bind9/cur/
In each release directory, you will find:

File Name
Description

README.md
A brief introduction to BIND

RELEASE-NOTES-bind-*.html
Release notes (the most significant changes)

CHANGELOG-bind-*.html
Detailed change log

COPYRIGHT
Copyright notices for BIND and included software

LIC ...</description>
      <pubDate>Wed, 27 May 2026 05:25:53 GMT</pubDate>
      <category>BIND 9 &gt; Release Notes</category>
      <link>https://kb.isc.org/docs/a-note-about-bind-release-notes</link>
      <guid>https://kb.isc.org/docs/a-note-about-bind-release-notes</guid>
    </item>
    <item>
      <title>Kea: Use unique databases</title>
      <description>Summary
When configuring Kea to use a database for storage of leases or host reservations, use a unique database for each Kea server.
Within a single Kea high availability group (HA group), the database may be shared, subject to certain considerations.
Guidance
Use a unique database for every Kea server.
A database can be made unique by creating a different database name on the same database server, or by using different database servers.  For example, if you use a central database server, creat ...</description>
      <pubDate>Wed, 20 May 2026 13:05:54 GMT</pubDate>
      <category>Kea DHCP &gt; Configuring Kea</category>
      <link>https://kb.isc.org/docs/kea-unique-databases</link>
      <guid>https://kb.isc.org/docs/kea-unique-databases</guid>
    </item>
    <item>
      <title>BIND 9 Software Vulnerability Matrix</title>
      <description>The BIND 9 Software Vulnerability Matrix (previously know as the "BIND 9 Security Vulnerability Matrix") is a tool to help DNS operators understand the current security risk for a given version of BIND. It has two parts:

The first part is a table listing all of the vulnerabilities covered by this page. The first column is a reference number for use in the tables in the second part. The second column is the CVE (Common Vulnerabilities and Exposure) number for the vulnerability, linked to its pag ...</description>
      <pubDate>Wed, 20 May 2026 11:39:14 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/aa-00913</link>
      <guid>https://kb.isc.org/docs/aa-00913</guid>
    </item>
    <item>
      <title>CVE-2026-5950: Unbounded resend loop in BIND 9 resolver</title>
      <description>CVE: CVE-2026-5950
Title: Unbounded resend loop in BIND 9 resolver
Document version: 2.0
Posting date: 20 May 2026
Program impacted: BIND 9
Versions affected:
BIND

9.18.36 -&gt; 9.18.48
9.20.8 -&gt; 9.20.22
9.21.7 -&gt; 9.21.21

BIND Supported Preview Edition

9.18.36-S1 -&gt; 9.18.48-S1
9.20.9-S1 -&gt; 9.20.22-S1

Severity: Medium
Exploitable: Remotely
Description:
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated  ...</description>
      <pubDate>Wed, 20 May 2026 11:16:24 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/cve-2026-5950</link>
      <guid>https://kb.isc.org/docs/cve-2026-5950</guid>
    </item>
    <item>
      <title>CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior</title>
      <description>CVE: CVE-2026-5947
Title: SIG(0) validation during query flood may lead to undefined behavior
Document version: 2.0
Posting date: 20 May 2026
Program impacted: BIND 9
Versions affected:
BIND

9.20.0 -&gt; 9.20.22
9.21.0 -&gt; 9.21.21

BIND Supported Preview Edition

9.20.9-S1 -&gt; 9.20.22-S1

Versions NOT affected:
BIND

9.18.28 -&gt; 9.18.49

BIND Supported Preview Edition

9.18.28-S1 -&gt; 9.18.49-S1

(Versions prior to 9.18.28 were not assessed.)
Severity: High
Exploitable: Remotely
Description:
Undefined  ...</description>
      <pubDate>Wed, 20 May 2026 11:11:29 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/cve-2026-5947</link>
      <guid>https://kb.isc.org/docs/cve-2026-5947</guid>
    </item>
    <item>
      <title>CVE-2026-5946:  Invalid handling of CLASS != IN</title>
      <description>CVE: CVE-2026-5946
Title: Invalid handling of CLASS != IN
Document version: 2.0
Posting date: 20 May 2026
Program impacted: BIND 9
Versions affected:
BIND

9.11.0 -&gt; 9.16.50
9.18.0 -&gt; 9.18.48
9.20.0 -&gt; 9.20.22
9.21.0 -&gt; 9.21.21

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.16.50-S1
9.18.11-S1 -&gt; 9.18.48-S1
9.20.9-S1 -&gt; 9.20.22-S1

Severity: High
Exploitable: Remotely
Description:
Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (I ...</description>
      <pubDate>Wed, 20 May 2026 11:06:54 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/cve-2026-5946</link>
      <guid>https://kb.isc.org/docs/cve-2026-5946</guid>
    </item>
    <item>
      <title>CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records</title>
      <description>CVE: CVE-2026-3592
Title: Amplification vulnerabilities via self-pointed glue records
Document version: 2.0
Posting date: 20 May 2026
Program impacted: BIND 9
Versions affected:
BIND

9.11.0 -&gt; 9.16.50
9.18.0 -&gt; 9.18.48
9.20.0 -&gt; 9.20.22
9.21.0 -&gt; 9.21.21

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.16.50-S1
9.18.11-S1 -&gt; 9.18.48-S1
9.20.9-S1 -&gt; 9.20.22-S1

Severity: Medium
Exploitable: Remotely
Description:
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. ...</description>
      <pubDate>Wed, 20 May 2026 11:03:24 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/cve-2026-3592</link>
      <guid>https://kb.isc.org/docs/cve-2026-3592</guid>
    </item>
    <item>
      <title>CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation</title>
      <description>CVE: CVE-2026-3593
Title: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
Document version: 2.0
Posting date: 20 May 2026
Program impacted: BIND 9
Versions affected:
BIND

9.20.0 -&gt; 9.20.22
9.21.0 -&gt; 9.21.21

BIND Supported Preview Edition

9.20.9-S1 -&gt; 9.20.22-S1

Versions NOT affected:
BIND

9.18.0 -&gt; 9.18.48

BIND Supported Preview Edition

9.18.11-S1 -&gt; 9.18.48-S1

(Versions prior to 9.18.0 and 9.18.11-S1 were not assessed.)
Severity: High
Exploitable: Remotely
Desc ...</description>
      <pubDate>Wed, 20 May 2026 10:56:07 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/cve-2026-3593</link>
      <guid>https://kb.isc.org/docs/cve-2026-3593</guid>
    </item>
    <item>
      <title>CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation</title>
      <description>CVE: CVE-2026-3039
Title: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
Document version: 2.0
Posting date: 20 May 2026
Program impacted: BIND 9
Versions affected:
BIND

9.0.0 -&gt; 9.16.50
9.18.0 -&gt; 9.18.48
9.20.0 -&gt; 9.20.22
9.21.0 -&gt; 9.21.21

BIND Supported Preview Edition

9.9.3-S1 -&gt; 9.16.50-S1
9.18.11-S1 -&gt; 9.18.48-S1
9.20.9-S1 -&gt; 9.20.22-S1

(Versions prior to 9.11.37 were not assessed.)
Although we have not tested them individually, we believe that all EoL versions of BIND  ...</description>
      <pubDate>Wed, 20 May 2026 10:48:38 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/cve-2026-3039</link>
      <guid>https://kb.isc.org/docs/cve-2026-3039</guid>
    </item>
    <item>
      <title>Things to be aware of when upgrading to Kea 3.0.0</title>
      <description>The release of the Kea 3.0 branch brings with it many changes users need to know about.
Hooks libraries re-licensed and re-packaged
Most Kea hook libraries have become open source and are freely available; the only exceptions are the Role-Based Access Control hook (RBAC) and the Configuration Backend hook (CB), which remain commercially licensed. The open source hook libraries will be available in the Kea source tarball and for package installation from the official ISC repositories on Cloudsmit ...</description>
      <pubDate>Thu, 14 May 2026 21:27:41 GMT</pubDate>
      <category>Kea DHCP &gt; Upgrading Kea</category>
      <link>https://kb.isc.org/docs/things-to-be-aware-of-when-upgrading-to-kea-300</link>
      <guid>https://kb.isc.org/docs/things-to-be-aware-of-when-upgrading-to-kea-300</guid>
    </item>
    <item>
      <title>Stork Quickstart guide</title>
      <description>Introduction
Installing Stork can seem somewhat confusing at first.  The purpose of this quickstart guide is to layout the installation process in steps grouped by package manager or OS.  Choose your OS/package manager from the table of contents on the right hand side to jump directly to the section that will cover the installation on your system.
Stork Agent

Since the Stork Agent may need to be installed more than once on disparate systems (example: to monitor BIND and Kea installations which  ...</description>
      <pubDate>Wed, 13 May 2026 11:45:16 GMT</pubDate>
      <category>Stork</category>
      <link>https://kb.isc.org/docs/stork-quickstart-guide</link>
      <guid>https://kb.isc.org/docs/stork-quickstart-guide</guid>
    </item>
    <item>
      <title>A short introduction to Catalog Zones</title>
      <description>Catalog Zones is a BIND feature allowing easy provisioning of zones to secondary servers. A "catalog zone" is a special DNS zone that contains a list of other zones to be served, along with their configuration parameters.  The zones listed in a catalog zone are called "member zones".  When a catalog zone is loaded or transferred to a secondary server that supports this functionality, the secondary server creates the member zones automatically.  When the catalog zone is updated (for example, to a ...</description>
      <pubDate>Wed, 13 May 2026 08:12:49 GMT</pubDate>
      <category>BIND 9 &gt; Authoritative Configuration and Operation</category>
      <link>https://kb.isc.org/docs/aa-01401</link>
      <guid>https://kb.isc.org/docs/aa-01401</guid>
    </item>
    <item>
      <title>General Best Practices for Servers</title>
      <description>Introduction
Operators should strive to implement general best practices for the servers hosting their critical infrastructure.  Software is only as good as the platform it runs on.
System administration is well beyond the scope and remit of ISC Support.  However, we can offer a very few suggestions, based on the most common problems we see.
Keep current

Use an operating system which is still being maintained
Keep current with security and stability updates (patches/fixes)

ISC gets many report ...</description>
      <pubDate>Tue, 12 May 2026 18:37:59 GMT</pubDate>
      <category>About ISC</category>
      <link>https://kb.isc.org/docs/server-best-practices</link>
      <guid>https://kb.isc.org/docs/server-best-practices</guid>
    </item>
    <item>
      <title>Kea API and Control Sockets</title>
      <description>Introduction
This article introduces the Kea Application Programming Interface (API).  It briefly discusses the architecture of how the Kea API is presented, through control sockets, the direct API, and the Kea Control Agent (KCA).
Use of API commands is beyond the scope of this article.  Consult the Kea ARM for information on API commands and their usage.
Kea API Overview
The Kea DHCP server consists of up to four daemons (service processes).  These daemons communicate with each other, and with ...</description>
      <pubDate>Tue, 12 May 2026 15:39:44 GMT</pubDate>
      <category>Kea DHCP</category>
      <link>https://kb.isc.org/docs/kea-api-sockets</link>
      <guid>https://kb.isc.org/docs/kea-api-sockets</guid>
    </item>
    <item>
      <title>ISC's Software Support Policy and Version Numbering</title>
      <description>The purpose of this article is to help users determine how long a given ISC release is likely to be supported. This information is useful when deciding when to schedule a migration, or in some cases, to help determine which version to migrate to when updating. This is a rough guide, not a guarantee, and release dates are approximate.
For the most current information on the status of any particular software version, please refer to the software status listed on the downloads page.
BIND 9 (updated ...</description>
      <pubDate>Mon, 11 May 2026 12:46:10 GMT</pubDate>
      <category>About ISC</category>
      <link>https://kb.isc.org/docs/aa-00896</link>
      <guid>https://kb.isc.org/docs/aa-00896</guid>
    </item>
    <item>
      <title>Kea Database Connection Resilience</title>
      <description>Introduction
This document discusses database connectivity problems, parameters that can be adjusted to make Kea compensate for those problems, and some of the implications of doing so.
Scenario
Symptoms
Often this discussion begins with error messages like this:
DATABASE_MYSQL_FATAL_ERROR Unrecoverable MySQL error occurred: unable to execute for &lt;SELECT ...&gt;, reason: Server has gone away (error code: 2006).
DHCP6_PACKET_PROCESS_STD_EXCEPTION ... exception occurred during packet processing: fata ...</description>
      <pubDate>Fri, 08 May 2026 21:25:34 GMT</pubDate>
      <category>Kea DHCP &gt; Troubleshooting Kea</category>
      <link>https://kb.isc.org/docs/kea-database-resilience</link>
      <guid>https://kb.isc.org/docs/kea-database-resilience</guid>
    </item>
    <item>
      <title>ISC Support Subscriber News Q1 2026</title>
      <description>
         Your browser does not support PDF.click here to download
</description>
      <pubDate>Thu, 02 Apr 2026 20:15:33 GMT</pubDate>
      <category>About ISC &gt; Support Subscriber Newsletter</category>
      <link>https://kb.isc.org/docs/isc-support-subscriber-news-q1-2026</link>
      <guid>https://kb.isc.org/docs/isc-support-subscriber-news-q1-2026</guid>
    </item>
    <item>
      <title>Operational Notification: Impact of Stricter Glue Checking</title>
      <description>Title: Operational Notification: Impact of Stricter Glue Checking
Document Version: 1.0a
Posting date: 15 December 2025
Canonical URL: https://kb.isc.org/docs/strict-glue
Program impacted: BIND
Versions affected:
BIND

9.18.41 and later
9.20.15 and later
9.21.14 and later

Description:
BIND versions released in October 2025 included changes in how BIND processes referrals in delegations.  BIND now only trusts glue records if, in the associated NS record, the target name (right side) is a subdoma ...</description>
      <pubDate>Thu, 02 Apr 2026 14:59:34 GMT</pubDate>
      <category>BIND 9 &gt; Operational Notifications</category>
      <link>https://kb.isc.org/docs/strict-glue</link>
      <guid>https://kb.isc.org/docs/strict-glue</guid>
    </item>
    <item>
      <title>Ports used by Kea</title>
      <description>Introduction
This article summarizes the TCP and UDP ports (service ports) used by the Kea DHCP server.
Standard Ports
These ports are specified by the various protocols Kea implements and uses.  They are documented here for completeness.  Changing them is generally impractical, outside of very controlled circumstances (e.g., a lab environment).

Proto
Port
Assignment

UDP
67
DHCPv4 server

UDP
68
DHCPv4 client

UDP
546
DHCPv6 server

UDP
547
DHCPv6 client

Both
53
DNS

The "Proto" column gives  ...</description>
      <pubDate>Wed, 01 Apr 2026 19:12:44 GMT</pubDate>
      <category>Kea DHCP &gt; Configuring Kea</category>
      <link>https://kb.isc.org/docs/kea-ports</link>
      <guid>https://kb.isc.org/docs/kea-ports</guid>
    </item>
  </channel>
</rss>