Gnoppix Security Announcement - 2026-07-22T20:00:51.901-04:00

Gnoppix Security Advisory GSA-6395-1: BIND9 Flaw Permits Denial of Service

A critical security vulnerability has been identified in BIND9, the widely used DNS server software. A remote attacker can exploit this flaw to cause a denial of service, crashing the named process.

Who is affected?
All systems running BIND9 versions included in Gnoppix 23/25 (stable) and Gnoppix 25 (testing) are at risk. This includes both authoritative and recursive server configurations.

The vulnerability
The flaw resides in how BIND9 handles specific crafted DNS messages. Sending a malformed query or response can trigger an assertion failure in the parsing code, leading to an immediate service termination.

What to do
Administrators must upgrade their BIND9 packages immediately.

Action required: Apply the security update without delay to prevent service interruptions.

How to upgrade
Use the standard package manager to install the fixed version. The update patches the vulnerable component and restores normal operation.

Background

BIND9 is a critical component of internet infrastructure, translating domain names to IP addresses. An unpatched server leaves networks vulnerable to easy attacks.

The update pushes version 9.18.x to all affected systems. No workarounds are provided; the only safe mitigation is the full patch installation. - Please update your systems.