Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. An attacker controlling ANY DNSSEC-signed zone can craft NSEC records spanning into victim zones, enabling cross-zone cache poisoning with AD=1 (Authenticated Data flag set)
ISC DHCP is not affected by CVE-2026-13321. This is a BIND server-side DNSSEC validation issue; ISC DHCP does not perform DNSSEC validation. ISC DHCP uses portions of the ISC BIND libraries (primarily libdns, omapi, and libisccfg) only to support DDNS (TSIG support, DNS message construction/parsing, DHCID generation), OMAPI-related operations, and basic functions (configuration handling, data structures, logging, networking primitives).