Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE: 2024:0319-1 moderate: coredns performance enhancement

opensuse
Calendar Grey September 27, 2024
Dist Opensuse Esm H88
This patch fixes various bugs in dnsmasq, improving efficiency and tackling identified vulnerabilities in Fedora.
An update that fixes 6 vulnerabilities is now available

Description

This update for coredns fixes the following issues:

Update to version 1.11.3:

* optimize the performance for high qps (#6767)

* bump deps

* Fix zone parser error handling (#6680)

* Add alternate option to forward plugin (#6681)

* fix: plugin/file: return error when parsing the file fails (#6699)

* [fix:documentation] Clarify autopath README (#6750)

* Fix outdated test (#6747)

* Bump go version from 1.21.8 to 1.21.11 (#6755)

* Generate zplugin.go correctly with third-party plugins (#6692)

* dnstap: uses pointer receiver for small response writer (#6644)

* chore: fix function name in comment (#6608)

* [plugin/forward] Strip local zone from IPV6 nameservers (#6635)

- fixes CVE-2023-30464

- fixes CVE-2023-28452

Update to upstream head (git commit #5a52707):

* bump deps to address security issue CVE-2024-22189

* Return RcodeServerFailure when DNS64 has no next plugin (#6590)

* add plusserver to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2024-319=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 x86_64):

coredns-1.11.3-bp156.4.3.1

- openSUSE Backports SLE-15-SP6 (noarch):

coredns-extras-1.11.3-bp156.4.3.1

References

https://www.suse.com/security/cve/CVE-2022-27191.html

https://www.suse.com/security/cve/CVE-2022-28948.html

https://www.suse.com/security/cve/CVE-2023-28452.html

https://www.suse.com/security/cve/CVE-2023-30464.html

https://www.suse.com/security/cve/CVE-2024-0874.html

https://www.suse.com/security/cve/CVE-2024-22189.html

Announcement ID: openSUSE-SU-2024:0319-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here