Internet Systems Consortium released BIND 9 updates to address fourteen distinct security vulnerabilities.

Reader brief
Through the Reader lens: The Internet Systems Consortium has released patches for BIND 9 to address fourteen security vulnerabilities discovered in its DNS software. These flaws range from remote crashes that can be triggered by unauthenticated requests to issues affecting DNSSEC validation and zone data integrity. While no active exploitation has been reported, the organization has provided reproduction tests that detail the conditions necessary to trigger these vulnerabilities. Users on the supported 9.20 and 9.21 branches are advised to update, while those on the discontinued 9.18 branch remain vulnerable without a fix.
What to watch next
- Monitoring for potential exploitation attempts given the availability of reproduction tests.
- Deployment of updated BIND packages by operating system maintainers.
- Potential for further vulnerability disclosures as ISC continues monthly maintenance releases.
Sources1
- [1]The Hacker NewsneutralBIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS