openSUSE-SU-2026:21533-1: important: Security update for dnsdist

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for dnsdist
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21533-1
Rating: important
References:

  * bsc#1269201
  * bsc#1269202
  * bsc#1269203
  * bsc#1269204
  * bsc#1269205
  * bsc#1269206
  * bsc#1269207



Cross-References:

  * CVE-2026-40011
  * CVE-2026-40208
  * CVE-2026-40209
  * CVE-2026-40210
  * CVE-2026-40211
  * CVE-2026-42004
  * CVE-2026-42005



CVSS scores:

  * CVE-2026-40011 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-40011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-40208 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-40208 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-40209 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-40209 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-40210 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
  * CVE-2026-40210 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-40211 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-40211 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-42004 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-42004 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-42005 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-42005 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.

Description:

This update for dnsdist fixes the following issues:

Update to 1.9.15.

Changes for dnsdist:

- https://www.dnsdist.org/changelog.html#change-1.9.15
- https://www.dnsdist.org/changelog.html#change-1.9.14

Security issues fixed:

- CVE-2026-40011: invalid output produced in the prometheus endpoint when a large number of crafted DNS queries are sent
  (bsc#1269204).
- CVE-2026-40208: processing of DoH3 queries can be delayed via DoH3 GET queries with an invalid DATA frames
  (bsc#1269207).
- CVE-2026-40209: outgoing TCP connections to backend can get stuck until a timeout occurs when specially crafted IXFR
  queries are sent (bsc#1269206).
- CVE-2026-40210: out-of-bounds read when `SetMacAddrAction` is used can lead to uninitialized memory being sent over
  the network or a crash (bsc#1269205).
- CVE-2026-40211: crafted DNS over HTTP/3 queries can trigger an exception that prevents memory from being freed and can
  lead to an OOM condition (bsc#1269203).
- CVE-2026-42004: crafted EDNS OPT record will be ignored by filtering rules, but will be rewritten as a valid OPT
  record when EDNS Client Subnet is inserted (bsc#1269202).
- CVE-2026-42005: crafted web request can cause unlimited memory allocation in the internal web server and lead to a DoS
  (bsc#1269201).


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1432=1

Package List:

- openSUSE Leap 16.0:

  dnsdist-1.9.15-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-40011.html
  * https://www.suse.com/security/cve/CVE-2026-40208.html
  * https://www.suse.com/security/cve/CVE-2026-40209.html
  * https://www.suse.com/security/cve/CVE-2026-40210.html
  * https://www.suse.com/security/cve/CVE-2026-40211.html
  * https://www.suse.com/security/cve/CVE-2026-42004.html
  * https://www.suse.com/security/cve/CVE-2026-42005.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.