This update for coredns fixes the following issues:
Update to version 1.11.3:
* optimize the performance for high qps (#6767)
* bump deps
* Fix zone parser error handling (#6680)
* Add alternate option to forward plugin (#6681)
* fix: plugin/file: return error when parsing the file fails (#6699)
* [fix:documentation] Clarify autopath README (#6750)
* Fix outdated test (#6747)
* Bump go version from 1.21.8 to 1.21.11 (#6755)
* Generate zplugin.go correctly with third-party plugins (#6692)
* dnstap: uses pointer receiver for small response writer (#6644)
* chore: fix function name in comment (#6608)
* [plugin/forward] Strip local zone from IPV6 nameservers (#6635)
- fixes CVE-2023-30464
- fixes CVE-2023-28452
Update to upstream head (git commit #5a52707):
* bump deps to address security issue CVE-2024-22189
* Return RcodeServerFailure when DNS64 has no next plugin (#6590)
* add plusserver to...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2024-319=1
- openSUSE Backports SLE-15-SP6 (aarch64 i586 x86_64):
coredns-1.11.3-bp156.4.3.1
- openSUSE Backports SLE-15-SP6 (noarch):
coredns-extras-1.11.3-bp156.4.3.1
https://www.suse.com/security/cve/CVE-2022-27191.html
https://www.suse.com/security/cve/CVE-2022-28948.html
https://www.suse.com/security/cve/CVE-2023-28452.html
https://www.suse.com/security/cve/CVE-2023-30464.html
https://www.suse.com/security/cve/CVE-2024-0874.html
https://www.suse.com/security/cve/CVE-2024-22189.html
Get the latest Linux and open source security news straight to your inbox.