Bug 2480539

Summary: Please update bind: CVE-2026-3592 CVE-2026-3039 CVE-2026-5946 CVE-2026-5950
Product: [Fedora] Fedora Reporter: Edgar Hoch <edgar.hoch>
Component: bindAssignee: Petr Menšík <pemensik>
Status: CLOSED DUPLICATE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: rawhideCC: anon.amish, dns-sig, mruprich, ondrej, pemensik, zdohnal
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-05-21 17:33:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Edgar Hoch 2026-05-21 16:30:57 UTC
There exists several security bugs in bind, with have severity high and are remotely exploitable.

https://kb.isc.org/docs/cve-2026-3592
https://kb.isc.org/docs/cve-2026-3039
https://kb.isc.org/docs/cve-2026-5946
https://kb.isc.org/docs/cve-2026-5950

Please provide updates with the new versions of bind which fixes these bugs.


Reproducible: Always

Comment 1 Petr Menšík 2026-05-21 17:33:44 UTC
Yes, I know about them obviously. But ISC does not give us time enough time to prepare fixes for RHEL in advance. I should be fixing first all releases of paying customers first. But only updating versions and rebase takes not so much time, started with them already.

*** This bug has been marked as a duplicate of bug 2480121 ***

Comment 2 Ondřej Surý 2026-05-24 17:11:58 UTC
Petr Menšík - since you posted this on the public bug tracker forum, I have to respond publicly as well.  You've been told several times that there is a process in place and we are treating everyone the same.  I would appreciate if you stop playing the victim here.  Your employer makes money by supporting old and unsupported versions of software, that is your business decision.  There is no obligation from **any** open-source vendor to help your employer make money.  And there is no obligation to treat RedHat any other because RH made a business decision to freeze the upstream version to a random snapshot of the upstream software, add patches on top of that and then pretend this is more secure or more stable than properly maintained upstream version.  It is not ISC business to fix your business decisions or business processes.  IBM is multi-billion (in revenue) company, so it is well within RH capabilities to have all patches backported within two days, it is not ISC fault that you are the only maintainer doing this job.

So, let me repeat that again, stop attacking ISC via various channels and stop playing being the victim here.