Hi Emmanuel, * Emmanuel Arias <[email protected]> [2026-06-29 17:25]:
Hello team!I've prepared some patches to fix some CVE for bind9 [0]. Please, could you review it? In the order hand, I looked at CVE-2025-40777, and I didn't found a patch for 9.16, and the current patch listed in security-tracker is not so easy to backport, any thought? [0] https://salsa.debian.org/lts-team/packages/bind9/-/tree/debian/bullseye
debian/patches/0047-Skip-deny-answer-address-for-non-IN-addresses.patch is missing from debian/patches/series.
I did not follow the patches too deeply given upstream still maintains the branch.
Looks ok to me over all.There are patches for a couple new CVEs in https://gitlab.isc.org/isc-projects/bind9/-/tree/bind-9.16
Cheers Jochen
signature.asc
Description: PGP signature
