shield
Security update for dnsdist
SUSE-SLE-Module-Basesystem-15-SP7-2026-1618
This update for dnsdist fixes the following issues: Update to version 1.9.12. - https://www.dnsdist.org/changelog.html#change-1.9.12 Security issues fixed: - CVE-2026-0396: crafted DNS queries triggering domain-based dynamic rules can lead to HTML injection in the web dashboard (bsc#1261236). - CVE-2026-0397: misconfiguration of the CORS policy can lead to information disclosure (bsc#1261237). - CVE-2026-24028: crafted DNS packet parsed by Lua code using `newDNSPacketOverlay` can lead to an out-of-bounds read (bsc#1261238). - CVE-2026-24029: disabled option on a DNS over HTTPS nghttp2 frontend allows clients to bypass ACLs and send DoH queries (bsc#1261239). - CVE-2026-24030: crafted DoQ and DoH3 queries can lead to unbounded memory allocation and DoS (bsc#1261240). - CVE-2026-27853: crafted DNS responses sent to a DNSdist using certain methods in custom Lua code (`changeName`) can lead to an out-of-bounds write (bsc#1261243). - CVE-2026-27854: crafted DNS queries sent to a DNSdist using the `DNSQuestion:getEDNSOptions` method in custom Lua code can lead to a use-after-free (bsc#1261241).
-
Release DateApr 24 2026
-
ReferencesBugzilla: 1261241, 1261239, 1261236, 1261238, 1261243, 1261237, 1261240
CVEs: CVE-2026-24029, CVE-2026-0397, CVE-2026-24028, CVE-2026-27853, CVE-2026-0396, CVE-2026-24030, CVE-2026-27854 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.7 s390x
-
Packages
Basesystem Module 15.7 aarch64
-
Packages
Basesystem Module 15.7 ppc64le
-
Packages
Basesystem Module 15.7 x86_64
-
Packages