Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
There were reported regressions shortly after release of 9.18.41 and 9.20.15 version. Our builds should have them fixed. It failed on RHEL9 or RHEL10, where SHA-1 based signatures are considered insecure. When the domain is signed with both unsupported algorithm (such as 5 or 7) and supported algorithm at the same time, it resulted in SERVFAIL after CVE fixes applied. https://gitlab.isc.org/isc-projects/bind9/-/issues/5622 https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/11202
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:19912 https://access.redhat.com/errata/RHSA-2025:19912
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:19950 https://access.redhat.com/errata/RHSA-2025:19950
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:21034 https://access.redhat.com/errata/RHSA-2025:21034
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:21111 https://access.redhat.com/errata/RHSA-2025:21111
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:0420 https://access.redhat.com/errata/RHSA-2026:0420
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:0316 https://access.redhat.com/errata/RHSA-2026:0316
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:0326 https://access.redhat.com/errata/RHSA-2026:0326
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:0332 https://access.redhat.com/errata/RHSA-2026:0332
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:0702 https://access.redhat.com/errata/RHSA-2026:0702
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:0677 https://access.redhat.com/errata/RHSA-2026:0677
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:0674 https://access.redhat.com/errata/RHSA-2026:0674
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:0996 https://access.redhat.com/errata/RHSA-2026:0996
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:1541 https://access.redhat.com/errata/RHSA-2026:1541