It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service.
1:9.18.39-0ubuntu0.22.04.61:9.18.39-0ubuntu0.24.04.71:9.20.24-1ubuntu0.3