## This update for dnsdist fixes the following issues: Update to version 1.9.12. * https://www.dnsdist.org/changelog.html#change-1.9.12 Security issues fixed: * CVE-2026-0396: crafted DNS queries triggering domain-based dynamic rules can lead to HTML injection in the web dashboard (bsc#1261236). * CVE-2026-0397: misconfiguration of the CORS policy can lead to information disclosure (bsc#1261237). * CVE-2026-24028: crafted DNS packet parsed by Lua code using `newDNSPacketOverlay` can lead to an out-of-bounds read (bsc#1261238). * CVE-2026-24029: disabled option on a DNS over HTTPS nghttp2 frontend allows clients to bypass ACLs and send DoH queries (bsc#1261239). * CVE-2026-24030: crafted DoQ and DoH3 queries can lead to unbounded memory allocation and DoS (bsc#1261240).
* bsc#1261236
* bsc#1261237
* bsc#1261238
* bsc#1261239
* bsc#1261240
* bsc#1261241
* bsc#1261243
Cross-
* CVE-2026-0396
* CVE-2026-0397
* CVE-2026-24028
* CVE-2026-24029
* CVE-2026-24030
* CVE-2026-27853
* CVE-2026-27854
CVSS scores:
* CVE-2026-0396 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0396 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-0396 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-0396 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-0397 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0397 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Get the latest Linux and open source security news straight to your inbox.