BIND 9.20.29 and 9.21.26 fix 14 security vulnerabilities, including a high-severity flaw that lets an unauthenticated attacker crash the `named` DNS process through a single malicious DNS-over-HTTPS request. ISC says it has seen no active exploitation, but administrators should upgrade because the release also addresses resolver crashes, resource exhaustion, DNSSEC validation errors, and unauthorized zone data.
Source