Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE 15 SP6: Security Update 2025:0131-1 for CoreDNS Available

opensuse
Calendar Grey April 20, 2025
Dist Opensuse Esm H88
A security patch for coredns has been released on openSUSE, targeting one vulnerability categorized with moderate risk.
An update that solves one vulnerability and has one errata is now available

Description

This update for coredns fixes the following issues:

- Update to version 1.12.1:

* core: Increase CNAME lookup limit from 7 to 10 (#7153)

* plugin/kubernetes: Fix handling of pods having DeletionTimestamp set

* plugin/kubernetes: Revert "only create PTR records for endpoints with

hostname defined"

* plugin/forward: added option failfast_all_unhealthy_upstreams to

return servfail if all upstreams are down

* bump dependencies, fixing boo#1239294 and boo#1239728

- Update to version 1.12.0:

* New multisocket plugin - allows CoreDNS to listen on multiple sockets

* bump deps

- Update to version 1.11.4:

* forward plugin: new option next, to try alternate upstreams when

receiving specified response codes upstreams on (functions like the

external plugin alternate)

* dnssec plugin: new option to load keys from AWS Secrets Manager

* rewrite plugin: new option to revert EDNS0 option rewrites in responses

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-131=1

Package List

- openSUSE Backports SLE-15-SP6 (i586 x86_64):

coredns-1.12.1-bp156.4.6.5

- openSUSE Backports SLE-15-SP6 (noarch):

coredns-extras-1.12.1-bp156.4.6.5

References

https://www.suse.com/security/cve/CVE-2024-51744.html

https://bugzilla.suse.com/show_bug.cgi?id=1239294

https://bugzilla.suse.com/show_bug.cgi?id=1239728

Announcement ID: openSUSE-SU-2025:0131-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP6 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here