<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ISC Knowledgebase</title>
    <description />
    <link>https://kb.isc.org/docs</link>
    <atom:link href="https://kb.isc.org/rss/en" rel="self" type="application/rss+xml" />
    <item>
      <title>ISC's Software Support Policy and Version Numbering</title>
      <description>The purpose of this article is to help users determine how long a given ISC release is likely to be supported. This information is useful when deciding when to schedule a migration, or in some cases, to help determine which version to migrate to when updating. This is a rough guide, not a guarantee, and release dates are approximate.
For the most current information on the status of any particular software version, please refer to the software status listed on the downloads page.
BIND 9 (updated ...</description>
      <pubDate>Sat, 01 Aug 2026 11:32:57 GMT</pubDate>
      <category>About ISC</category>
      <link>https://kb.isc.org/docs/aa-00896</link>
      <guid>https://kb.isc.org/docs/aa-00896</guid>
    </item>
    <item>
      <title>Kea End-of-Life Dates</title>
      <description>The following table shows the approximate dates when ISC officially ended engineering support for these Kea releases. Typically, a release is end of life when another major version is issued.
EOL status means that the software development team is no longer testing, patching or issuing releases for that version.
ISC Support will generally provide support for any version they are able to. However, versions without engineering support will not receive new fixes, nor will we be able to call on engin ...</description>
      <pubDate>Fri, 31 Jul 2026 22:30:42 GMT</pubDate>
      <category>Kea DHCP</category>
      <link>https://kb.isc.org/docs/kea-end-of-life-dates</link>
      <guid>https://kb.isc.org/docs/kea-end-of-life-dates</guid>
    </item>
    <item>
      <title>Operational Notification: liburcu memory leak may impact BIND 9.20 on BSD</title>
      <description>Title: Operational Notification: liburcu memory leak may impact BIND 9.20 on BSD
Document Version: 1.0
Posting date: 29 July 2026
Canonical URL: https://kb.isc.org/docs/liburcu-leak
Program impacted: BIND
Versions affected:
BIND

9.20.0 and later

Description:
ISC is aware of an issue in the liburcu library which causes a memory leak on some platforms.  BIND 9.20 and later use this library, and experience the leak on affected platforms.  Older versions of BIND do not use this library and are not ...</description>
      <pubDate>Wed, 29 Jul 2026 14:18:40 GMT</pubDate>
      <category>BIND 9 &gt; Operational Notifications</category>
      <link>https://kb.isc.org/docs/liburcu-leak</link>
      <guid>https://kb.isc.org/docs/liburcu-leak</guid>
    </item>
    <item>
      <title>Kea HA Strategies Comparison</title>
      <description>Introduction
Kea's High Availability hook is the most popular solution for high availability operation. The Kea HA hook works by pairing Kea servers (a multi-node solution is also available), in either an active-active or active-passive collaboration scheme. In this way, the Kea servers can monitor each other and assume responsibility for answering on behalf of the other server in case of failure.
It is also possible for multiple Kea servers to leverage the lease 'backend' feature to share a sin ...</description>
      <pubDate>Wed, 22 Jul 2026 20:09:48 GMT</pubDate>
      <category>Kea DHCP &gt; Configuring Kea</category>
      <link>https://kb.isc.org/docs/kea-ha-strategies-comparison</link>
      <guid>https://kb.isc.org/docs/kea-ha-strategies-comparison</guid>
    </item>
    <item>
      <title>Kea Shared Lease Database Quickstart</title>
      <description>Introduction
In some cases, administrators may want to configure Kea to use the "Shared Lease Database" High Availability method.  This method has certain advantages when compared to the HA Hook.  The advantages and disadvantages of each method are covered in the Kea HA Strategies Comparison document.  In this document, the focus will be on configuring the Shared Lease Database method in Kea.
Both DHCPv4 and DHCPv6

Please note that the Shared Lease Database is relevant to both DHCPv4 and DHCPv6 ...</description>
      <pubDate>Wed, 22 Jul 2026 19:38:21 GMT</pubDate>
      <category>Kea DHCP &gt; Configuring Kea</category>
      <link>https://kb.isc.org/docs/kea-shared-lease-database-quickstart</link>
      <guid>https://kb.isc.org/docs/kea-shared-lease-database-quickstart</guid>
    </item>
    <item>
      <title>List of BIND Security Advisories</title>
      <description>Introduction
This is a complete list of all BIND security advisories, both current and historical.  Advisories apply only to particular versions of BIND, and this list makes no attempt to differentiate.
For information on which versions are vulnerable, see the  BIND 9 Software Vulnerability Matrix  instead.
Advisories are listed by date, most recent first.  The publication date is the date of formal public disclosure.  In this table, publication dates prior to 2022 may not be entirely accurate;  ...</description>
      <pubDate>Wed, 22 Jul 2026 13:27:39 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/all-bind-advisories</link>
      <guid>https://kb.isc.org/docs/all-bind-advisories</guid>
    </item>
    <item>
      <title>BIND 9 Software Vulnerability Matrix</title>
      <description>The BIND 9 Software Vulnerability Matrix details known security vulnerabilities in supported versions of BIND.  Vulnerabilities are identified by their CVE ID: Common Vulnerabilities and Exposures.
This page was previously called the "BIND 9 Security Vulnerability Matrix".
Using this matrix
Each row with a CVE ID gives the version(s) that fix that problem.
Determining vulnerability
To determine if/how a given version is vulnerable:

Find the column heading for the corresponding branch (9.X versi ...</description>
      <pubDate>Wed, 22 Jul 2026 13:07:07 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories</category>
      <link>https://kb.isc.org/docs/aa-00913</link>
      <guid>https://kb.isc.org/docs/aa-00913</guid>
    </item>
    <item>
      <title>CVE-2026-11721:  Cache poisoning possible with label count discrepancy, RRSIG, and wildcards</title>
      <description>CVE: CVE-2026-11721
Title: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.11.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels th ...</description>
      <pubDate>Wed, 22 Jul 2026 12:40:04 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-11721</link>
      <guid>https://kb.isc.org/docs/cve-2026-11721</guid>
    </item>
    <item>
      <title>CVE-2026-11622: Potential memory usage beyond configured limits</title>
      <description>CVE: CVE-2026-11622
Title: Potential memory usage beyond configured limits
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.11.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The  ...</description>
      <pubDate>Wed, 22 Jul 2026 12:36:35 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-11622</link>
      <guid>https://kb.isc.org/docs/cve-2026-11622</guid>
    </item>
    <item>
      <title>CVE-2026-10723: Incorrect acceptance of NSEC3 records</title>
      <description>CVE: CVE-2026-10723
Title: Incorrect acceptance of NSEC3 records
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.18.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: Medium
Exploitable: Remotely
Description:
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses.
Impact:
An att ...</description>
      <pubDate>Wed, 22 Jul 2026 12:32:43 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-10723</link>
      <guid>https://kb.isc.org/docs/cve-2026-10723</guid>
    </item>
    <item>
      <title>CVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present</title>
      <description>CVE: CVE-2026-13204
Title: Unexpected exit in certain situations with NSEC and NSEC3 both present
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.11.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for ...</description>
      <pubDate>Wed, 22 Jul 2026 12:29:10 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-13204</link>
      <guid>https://kb.isc.org/docs/cve-2026-13204</guid>
    </item>
    <item>
      <title>CVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME</title>
      <description>CVE: CVE-2026-12617
Title: Record ordering based unexpected exit with CNAME or DNAME
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.18.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24

BIND Supported Preview Edition

9.18.11-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Sp ...</description>
      <pubDate>Wed, 22 Jul 2026 12:24:46 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-12617</link>
      <guid>https://kb.isc.org/docs/cve-2026-12617</guid>
    </item>
    <item>
      <title>CVE-2026-11605: Unnecessary validation of DNSSEC signed records</title>
      <description>CVE: CVE-2026-11605
Title: Unnecessary validation of DNSSEC signed records
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A quer ...</description>
      <pubDate>Wed, 22 Jul 2026 12:20:21 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-11605</link>
      <guid>https://kb.isc.org/docs/cve-2026-11605</guid>
    </item>
    <item>
      <title>CVE-2026-11331: Potential wildcard CNAME RPZ policy bypass</title>
      <description>CVE: CVE-2026-11331
Title: Potential wildcard CNAME RPZ policy bypass
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.16.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.16.8-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLO ...</description>
      <pubDate>Wed, 22 Jul 2026 12:16:54 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-11331</link>
      <guid>https://kb.isc.org/docs/cve-2026-11331</guid>
    </item>
    <item>
      <title>CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field</title>
      <description>CVE: CVE-2026-13321
Title: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.11.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.11.3-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: High
Exploitable: Remotely
Description:
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.
Impact:
 ...</description>
      <pubDate>Wed, 22 Jul 2026 12:11:45 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-13321</link>
      <guid>https://kb.isc.org/docs/cve-2026-13321</guid>
    </item>
    <item>
      <title>CVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit</title>
      <description>CVE: CVE-2026-10822
Title: Key Record using PRIVATEDNS algorithm may lead to unexpected exit
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND

9.18.0 -&gt; 9.18.50
9.20.0 -&gt; 9.20.24
9.21.0 -&gt; 9.21.23

BIND Supported Preview Edition

9.18.11-S1 -&gt; 9.18.50-S1
9.20.9-S1 -&gt; 9.20.24-S1

Severity: Medium
Exploitable: Remotely
Description:
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subseq ...</description>
      <pubDate>Wed, 22 Jul 2026 12:06:31 GMT</pubDate>
      <category>BIND 9 &gt; Security Advisories &gt; 2026</category>
      <link>https://kb.isc.org/docs/cve-2026-10822</link>
      <guid>https://kb.isc.org/docs/cve-2026-10822</guid>
    </item>
    <item>
      <title>BIND 9.20-S Edition ARM</title>
      <description>The BIND9-S edition is distributed to ISC Support Subscribers at the Silver level and above.
A recent version of the Administrative Reference Manual is shared here, to facilitate understanding of what the -S Edition offers. If you are using the BIND9-S Edition, please instead consult the relevant version of the ARM, included in the distribution.
The file below is an epub format archive of the ARM for BIND version 9.20.25-S1.

          Bv9ARM-3.epub
</description>
      <pubDate>Wed, 15 Jul 2026 14:30:08 GMT</pubDate>
      <category>BIND 9 &gt; Navigating BIND documentation</category>
      <link>https://kb.isc.org/docs/bind-920-s-edition-arm</link>
      <guid>https://kb.isc.org/docs/bind-920-s-edition-arm</guid>
    </item>
    <item>
      <title>ISC Support Subscriber News Q2 2026</title>
      <description>
         Your browser does not support PDF.click here to download
</description>
      <pubDate>Tue, 30 Jun 2026 13:59:09 GMT</pubDate>
      <category>About ISC &gt; Support Subscriber Newsletter</category>
      <link>https://kb.isc.org/docs/isc-support-subscriber-news-q2-2026</link>
      <guid>https://kb.isc.org/docs/isc-support-subscriber-news-q2-2026</guid>
    </item>
    <item>
      <title>Using DLZ in BIND</title>
      <description>What is DLZ?
DLZ (Dynamically Loadable Zones) is a contributed extension to BIND 9 that allows zone data to be retrieved directly from an external database. There is no required format or schema.  DLZ drivers exist for several different database backends including PostgreSQL, MySQL, and LDAP and can be written for any other.
As of BIND 9.8, it is also possible to link some DLZ modules dynamically at runtime via the DLZ "dlopen" driver, which acts as a generic wrapper around a shared object that  ...</description>
      <pubDate>Mon, 29 Jun 2026 13:08:34 GMT</pubDate>
      <category>BIND 9 &gt; Zones &gt; Dynamically generating zone contents</category>
      <link>https://kb.isc.org/docs/aa-00995</link>
      <guid>https://kb.isc.org/docs/aa-00995</guid>
    </item>
    <item>
      <title>Kea Significant Features Matrix</title>
      <description>Private notes

Only visible to team accounts

This table lists the major feature differences for different releases of Kea. A "✔︎" in the table below indicates that feature is present in that branch. When all currently supported versions of Kea have the feature, we remove the row (because there is no difference to highlight).
See Release Notes for More Detailed Changes

This list does not include many smaller changes, including changes in existing features or minor new features. For more detail, ...</description>
      <pubDate>Wed, 24 Jun 2026 12:00:07 GMT</pubDate>
      <category>Kea DHCP</category>
      <link>https://kb.isc.org/docs/aa-01615</link>
      <guid>https://kb.isc.org/docs/aa-01615</guid>
    </item>
  </channel>
</rss>