Hide Forgot
Description of problem: Current release 9.11.4-P2 is not latest ESV release. Few features are not available. However, more imporant code change happened in 9.11.5 [1] release. - Many types in source code were changed, making most backported patches, including relative simple ones, not applicable without manual handwork. - Adds also support for kerberos based ACL rules: krb5-selfsub and ms-selfsub. Release 9.11.6-P1 [2] contains: - Fix for CVE-2019-6465 (bug #1683010) - Fix for CVE-2018-5745 (bug #1683016) - Fixes possible broken NSEC and NSEC3 signatures [3] Version-Release number of selected component (if applicable): bind-9.11.4-17.P2.el8 Additional info: 1. https://ftp.isc.org/isc/bind9/9.11.5/RELEASE-NOTES-bind-9.11.5.html 2. https://ftp.isc.org/isc/bind9/9.11.6/RELEASE-NOTES-bind-9.11.6.html 3. https://kb.isc.org/docs/dnssec-key-deletion-may-create-broken-nsec-and-nsec3-chains-and-unnecessary-rrsigs
According to release notes, only IDN features are changed in those releases. That part is originally from Red Hat, we already have downstream patches for it, it does not change behaviour of our version. Otherwise, should be safe.
Complete upstream release notes [1] list few more. Includes GeoIP2 feature, documented separately in bug #1564443. 1. https://downloads.isc.org/isc/bind9/9.11.13/RELEASE-NOTES-bind-9.11.13.html
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:1845