Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 30: 2019-7f92b28590 Major: Network Manager Security Flaw

fedora
Calendar Grey April 1, 2017
Dist Fedora Esm H88
Safety patch released for Knot Resolver in Fedora 26, tackling urgent vulnerabilities and introducing enhancements for better DNS performance.
new upstream release - security fix + security: Knot Resolver 1.2.0 and higher could return AD flag for insecure answer if the daemon received answer with invalid RRSIG several tim...

Summary

The Knot DNS Resolver is a caching full resolver implementation written in C

and LuaJIT, including both a resolver library and a daemon. Modular

architecture of the library keeps the core tiny and efficient, and provides

a state-machine like API for extensions.

The package is pre-configured as local caching resolver.

To start using it, just start the local DNS socket:

BEWARE:

Because of https://bugzilla.redhat.com/show_bug.cgi?id=1366968

you need to switch your system to SELinux permissive mode.

Update Information:

new upstream release - security fix + security: Knot Resolver 1.2.0 and higher could return AD flag for insecure answer if the daemon received answer with invalid RRSIG several times in a row. + fix: layer/iterate: some improvements in cname chain unrolling + fix: layer/validate: fix duplicate records in AUTHORITY section in case + fix: of WC expansion proof + fix: lua: do *not* truncate cache size to unsigned + fix: forwarding mode: correctly forward +cd flag + fix: fix a potential memory leak + fix: don't treat answers that contain DS non-existance proof as insecure + fix: don't store NSEC3 and their signatures in the cache + fix: layer/iterate: when processing delegations, check if qname is at or below new authority + enhancement: modules/policy: allow QTRACE policy to be chained with other policies + enhancement: hints.add_hosts(path): a new property + enhancement: module: document the API and simplify the code + enhancement: policy.MIRROR: support IPv6 link-local addresses + en...

Change Log

References

Fedora Update Notification FEDORA-2017-45ebf1e164 2017-04-01 16:46:19.646541
Name : knot-resolver Product : Fedora 26 Version : 1.2.4 Release : 1.fc26 URL : https://www.knot-resolver.cz/ Summary : Caching full DNS Resolver Description : The Knot DNS Resolver is a caching full resolver implementation written in C and LuaJIT, including both a resolver library and a daemon. Modular architecture of the library keeps the core tiny and efficient, and provides a state-machine like API for extensions.
The package is pre-configured as local caching resolver. To start using it, just start the local DNS socket:

BEWARE: Because of https://bugzilla.redhat.com/show_bug.cgi?id=1366968 you need to switch your system to SELinux permissive mode.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade knot-resolver' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: knot-resolver
Product: Fedora 26
Version: 1.2.4
Release: 1.fc26
Summary: Caching full DNS Resolver

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here