Bug 2480539 - Please update bind: CVE-2026-3592 CVE-2026-3039 CVE-2026-5946 CVE-2026-5950
Summary: Please update bind: CVE-2026-3592 CVE-2026-3039 CVE-2026-5946 CVE-2026-5950
Keywords:
Status: CLOSED DUPLICATE of bug 2480121
Alias: None
Product: Fedora
Classification: Fedora
Component: bind
Version: rawhide
Hardware: All
OS: Linux
unspecified
urgent
Target Milestone: ---
Assignee: Petr Menšík
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-21 16:30 UTC by Edgar Hoch
Modified: 2026-05-24 17:11 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-05-21 17:33:44 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Edgar Hoch 2026-05-21 16:30:57 UTC
There exists several security bugs in bind, with have severity high and are remotely exploitable.

https://kb.isc.org/docs/cve-2026-3592
https://kb.isc.org/docs/cve-2026-3039
https://kb.isc.org/docs/cve-2026-5946
https://kb.isc.org/docs/cve-2026-5950

Please provide updates with the new versions of bind which fixes these bugs.


Reproducible: Always

Comment 1 Petr Menšík 2026-05-21 17:33:44 UTC
Yes, I know about them obviously. But ISC does not give us time enough time to prepare fixes for RHEL in advance. I should be fixing first all releases of paying customers first. But only updating versions and rebase takes not so much time, started with them already.

*** This bug has been marked as a duplicate of bug 2480121 ***

Comment 2 Ondřej Surý 2026-05-24 17:11:58 UTC
Petr Menšík - since you posted this on the public bug tracker forum, I have to respond publicly as well.  You've been told several times that there is a process in place and we are treating everyone the same.  I would appreciate if you stop playing the victim here.  Your employer makes money by supporting old and unsupported versions of software, that is your business decision.  There is no obligation from **any** open-source vendor to help your employer make money.  And there is no obligation to treat RedHat any other because RH made a business decision to freeze the upstream version to a random snapshot of the upstream software, add patches on top of that and then pretend this is more secure or more stable than properly maintained upstream version.  It is not ISC business to fix your business decisions or business processes.  IBM is multi-billion (in revenue) company, so it is well within RH capabilities to have all patches backported within two days, it is not ISC fault that you are the only maintainer doing this job.

So, let me repeat that again, stop attacking ISC via various channels and stop playing being the victim here.


Note You need to log in before you can comment on or make changes to this bug.