Vulnerabilities

BIND 9 on Linux: which version fixes what

The overwhelming majority of BIND advisories are remote crashes. That sounds mild until you remember that when the nameserver stops, everything that depends on a name stops with it.

SecAI tracks 155 distinct CVEs affecting BIND 9 across the 6 distributions below, of which 15 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.

What it is, and why it is on your server

BIND 9 is the most widely deployed DNS server software, packaged as bind9 on Debian and Ubuntu and bind on Rocky and AlmaLinux. It is also what many control panels install to serve a hosting account's zones.

Why its advisories behave the way they do

  • A crash is an outage, and named is frequently in front of everything. A specially formed query that kills the daemon takes down mail delivery and site resolution with it.
  • Recursion left open is the classic mistake. A resolver that answers the whole internet is both an amplification weapon pointed at someone else and a cache-poisoning target of its own.
  • The release cadence is brisk. ISC publishes several advisories a year and the distributions follow closely, so a BIND package more than a few months behind is usually genuinely behind.

Check what you are actually running

The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.

Debian and Ubuntu
dpkg-query -W -f='${Package} ${Version}\n' bind9 bind9-utils 2>/dev/null
Rocky Linux and AlmaLinux
rpm -q bind bind-utils

If you are not deliberately running a public resolver, check that you are not accidentally running one: `dig +short @your.server.ip example.com` from outside should not answer.

Fixed versions, per distribution

Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.

Ubuntu 22.04 LTSsource package: bind9

CVEPublishedFixed in package version
CVE-2026-190332026-09-16no fixed version released
CVE-2026-196622026-09-16no fixed version released
CVE-2026-196662026-09-16no fixed version released
CVE-2026-196672026-09-16no fixed version released
CVE-2026-196682026-09-16no fixed version released
CVE-2026-199412026-09-16no fixed version released
CVE-2026-750292026-09-16no fixed version released
CVE-2026-761632026-09-16no fixed version released
CVE-2026-771192026-09-16no fixed version released
CVE-2026-776922026-09-16no fixed version released
CVE-2026-783012026-09-16no fixed version released
CVE-2026-802742026-09-16no fixed version released
CVE-2026-815632026-09-16no fixed version released
CVE-2026-817362026-09-16no fixed version released
CVE-2026-132042026-08-311:9.18.39-0ubuntu0.22.04.6
CVE-2026-107232026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-108222026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-113312026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-116052026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-116222026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-117212026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-126172026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-133212026-08-191:9.18.39-0ubuntu0.22.04.5
CVE-2026-30392026-05-201:9.18.39-0ubuntu0.22.04.4
CVE-2026-35922026-05-201:9.18.39-0ubuntu0.22.04.4

Showing the 25 most recent of 61 that apply to Ubuntu 22.04 LTS, 14 of which have no fixed version released.

Ubuntu 24.04 LTSsource package: bind9

CVEPublishedFixed in package version
CVE-2026-190332026-09-16no fixed version released
CVE-2026-196622026-09-16no fixed version released
CVE-2026-196662026-09-16no fixed version released
CVE-2026-196672026-09-16no fixed version released
CVE-2026-196682026-09-16no fixed version released
CVE-2026-199412026-09-16no fixed version released
CVE-2026-750292026-09-16no fixed version released
CVE-2026-761632026-09-16no fixed version released
CVE-2026-771192026-09-16no fixed version released
CVE-2026-776922026-09-16no fixed version released
CVE-2026-783012026-09-16no fixed version released
CVE-2026-802742026-09-16no fixed version released
CVE-2026-815632026-09-16no fixed version released
CVE-2026-817362026-09-16no fixed version released
CVE-2026-132042026-08-311:9.18.39-0ubuntu0.24.04.7
CVE-2026-107232026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-108222026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-113312026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-116052026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-116222026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-117212026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-126172026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-133212026-08-191:9.18.39-0ubuntu0.24.04.6
CVE-2026-30392026-05-201:9.18.39-0ubuntu0.24.04.5
CVE-2026-35922026-05-201:9.18.39-0ubuntu0.24.04.5

Showing the 25 most recent of 39 that apply to Ubuntu 24.04 LTS, 14 of which have no fixed version released.

Debian 12 (bookworm)source package: bind9

CVEPublishedFixed in package version
CVE-2026-190332026-09-16no fixed version released
CVE-2026-196622026-09-16no fixed version released
CVE-2026-196662026-09-16no fixed version released
CVE-2026-196672026-09-16no fixed version released
CVE-2026-196682026-09-16no fixed version released
CVE-2026-199412026-09-16no fixed version released
CVE-2026-750292026-09-16no fixed version released
CVE-2026-761632026-09-16no fixed version released
CVE-2026-771192026-09-16no fixed version released
CVE-2026-776922026-09-16no fixed version released
CVE-2026-783012026-09-16no fixed version released
CVE-2026-802742026-09-16no fixed version released
CVE-2026-815632026-09-16no fixed version released
CVE-2026-817362026-09-16no fixed version released
CVE-2026-107232026-07-221:9.18.49-1~deb12u2
CVE-2026-108222026-07-221:9.18.49-1~deb12u2
CVE-2026-113312026-07-221:9.18.49-1~deb12u2
CVE-2026-116052026-07-221:9.18.49-1~deb12u2
CVE-2026-116222026-07-221:9.18.49-1~deb12u2
CVE-2026-117212026-07-221:9.18.49-1~deb12u2
CVE-2026-126172026-07-221:9.18.49-1~deb12u2
CVE-2026-132042026-07-221:9.18.49-1~deb12u2
CVE-2026-133212026-07-221:9.18.49-1~deb12u2
CVE-2026-30392026-05-201:9.18.49-1~deb12u2
CVE-2026-35922026-05-201:9.18.49-1~deb12u2

Showing the 25 most recent of 149 that apply to Debian 12 (bookworm), 15 of which have no fixed version released.

Debian 13 (trixie)source package: bind9

CVEPublishedFixed in package version
CVE-2026-190332026-09-161:9.20.29-1~deb13u1
CVE-2026-196622026-09-161:9.20.29-1~deb13u1
CVE-2026-196662026-09-161:9.20.29-1~deb13u1
CVE-2026-196672026-09-161:9.20.29-1~deb13u1
CVE-2026-196682026-09-161:9.20.29-1~deb13u1
CVE-2026-199412026-09-161:9.20.29-1~deb13u1
CVE-2026-750292026-09-161:9.20.29-1~deb13u1
CVE-2026-761632026-09-161:9.20.29-1~deb13u1
CVE-2026-771192026-09-161:9.20.29-1~deb13u1
CVE-2026-776922026-09-161:9.20.29-1~deb13u1
CVE-2026-783012026-09-161:9.20.29-1~deb13u1
CVE-2026-802742026-09-161:9.20.29-1~deb13u1
CVE-2026-815632026-09-161:9.20.29-1~deb13u1
CVE-2026-817362026-09-161:9.20.29-1~deb13u1
CVE-2026-107232026-07-221:9.20.26-1~deb13u1
CVE-2026-108222026-07-221:9.20.26-1~deb13u1
CVE-2026-113312026-07-221:9.20.26-1~deb13u1
CVE-2026-116052026-07-221:9.20.26-1~deb13u1
CVE-2026-116222026-07-221:9.20.26-1~deb13u1
CVE-2026-117212026-07-221:9.20.26-1~deb13u1
CVE-2026-126172026-07-221:9.20.26-1~deb13u1
CVE-2026-132042026-07-221:9.20.26-1~deb13u1
CVE-2026-133212026-07-221:9.20.26-1~deb13u1
CVE-2026-30392026-05-201:9.20.23-1~deb13u1
CVE-2026-35922026-05-201:9.20.23-1~deb13u1

Showing the 25 most recent of 155 that apply to Debian 13 (trixie).

Rocky Linux 9source package: bind

CVEPublishedFixed in package version
CVE-2026-107232026-08-142:9.16.23-40.el9_8.8
CVE-2026-113312026-08-142:9.16.23-40.el9_8.8
CVE-2026-116222026-08-142:9.16.23-40.el9_8.8
CVE-2026-117212026-08-142:9.16.23-40.el9_8.8
CVE-2026-132042026-08-142:9.16.23-40.el9_8.8
CVE-2026-133212026-08-142:9.16.23-40.el9_8.8
CVE-2026-30392026-06-112:9.16.23-40.el9_8.2
CVE-2026-59462026-06-112:9.16.23-40.el9_8.2
CVE-2025-86772026-05-282:9.16.23-40.el9_8.1
CVE-2026-15192026-04-152:9.16.23-34.el9_7.2
CVE-2025-407782025-11-212:9.16.23-34.el9_7.1
CVE-2025-407802025-11-212:9.16.23-34.el9_7.1
CVE-2024-111872025-03-172:9.16.23-24.el9_5.3
CVE-2024-17372024-08-212:9.16.23-18.el9_4.6
CVE-2024-19752024-08-212:9.16.23-18.el9_4.6
CVE-2024-40762024-08-212:9.16.23-18.el9_4.6
CVE-2023-44082024-05-102:9.16.23-18.el9_4.1
CVE-2023-503872024-05-102:9.16.23-18.el9_4.1
CVE-2023-508682024-05-102:9.16.23-18.el9_4.1
CVE-2023-55172024-05-102:9.16.23-18.el9_4.1
CVE-2023-56792024-05-102:9.16.23-18.el9_4.1
CVE-2023-65162024-05-102:9.16.23-18.el9_4.1
CVE-2023-33412023-10-142:9.16.23-11.el9_2.2
CVE-2023-28282023-08-082:9.16.23-11.el9_2.1
CVE-2021-252202022-11-152:9.16.23-5.el9_1

Showing the 25 most recent of 29 that apply to Rocky Linux 9.

AlmaLinux 9source package: bind

CVEPublishedFixed in package version
CVE-2026-107232026-08-1332:9.16.23-40.el9_8.8
CVE-2026-113312026-08-1332:9.16.23-40.el9_8.8
CVE-2026-116222026-08-1332:9.16.23-40.el9_8.8
CVE-2026-117212026-08-1332:9.16.23-40.el9_8.8
CVE-2026-132042026-08-1332:9.16.23-40.el9_8.8
CVE-2026-133212026-08-1332:9.16.23-40.el9_8.8
CVE-2026-30392026-06-0832:9.16.23-40.el9_8.2
CVE-2026-59462026-06-0832:9.16.23-40.el9_8.2
CVE-2025-86772026-05-1932:9.16.23-40.el9_8.1
CVE-2026-15192026-04-1432:9.16.23-34.el9_7.2
CVE-2025-407782025-11-1232:9.16.23-34.el9_7.1
CVE-2025-407802025-11-1232:9.16.23-34.el9_7.1
CVE-2024-111872025-02-1932:9.16.23-24.el9_5.3
CVE-2024-17372024-08-1532:9.16.23-18.el9_4.6
CVE-2024-19752024-08-1532:9.16.23-18.el9_4.6
CVE-2024-40762024-08-1532:9.16.23-18.el9_4.6
CVE-2023-44082024-04-3032:9.16.23-18.el9_4.1
CVE-2023-503872024-04-3032:9.16.23-18.el9_4.1
CVE-2023-508682024-04-3032:9.16.23-18.el9_4.1
CVE-2023-55172024-04-3032:9.16.23-18.el9_4.1
CVE-2023-56792024-04-3032:9.16.23-18.el9_4.1
CVE-2023-65162024-04-3032:9.16.23-18.el9_4.1
CVE-2023-33412023-10-1232:9.16.23-11.el9_2.2
CVE-2023-28282023-07-1732:9.16.23-11.el9_2.1
CVE-2022-27952023-05-0932:9.16.23-11.el9

Showing the 25 most recent of 33 that apply to AlmaLinux 9.

Advisory data last refreshed 26 September 2026. It is re-read daily.

What this page does not tell you

It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.

It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.

Read next

Find out which of these you are running

One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, BIND 9 included. It changes nothing.