This update for coredns fixes the following issues:
- CVE-2025-58063: Fixed Lease ID Confusion (bsc#1249389)
- Update to version 1.12.4:
* bump deps
* fix(transfer): goroutine leak on axfr err (#7516)
* plugin/etcd: fix import order for ttl test (#7515)
* fix(grpc): check proxy list length in policies (#7512)
* fix(https): propagate HTTP request context (#7491)
* fix(plugin): guard nil lookups across plugins (#7494)
* lint: add missing prealloc to backend lookup test (#7510)
* fix(grpc): span leak on error attempt (#7487)
* test(plugin): improve backend lookup coverage (#7496)
* lint: enable prealloc (#7493)
* lint: enable durationcheck (#7492)
* Add Sophotech to adopters list (#7495)
* plugin: Use %w to wrap user error (#7489)
* fix(metrics): add timeouts to metrics HTTP server (#7469)
* chore(ci): restrict token permissions (#7470)
* chore(ci): pin workflow dependencies (#7471)
*...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2025-401=1
- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64):
coredns-1.12.4-bp157.2.3.1
- openSUSE Backports SLE-15-SP7 (noarch):
coredns-extras-1.12.4-bp157.2.3.1
https://www.suse.com/security/cve/CVE-2025-58063.html
https://bugzilla.suse.com/1249389
Get the latest Linux and open source security news straight to your inbox.