Fix dual-signed domains verification, when one of algorithms is not supported.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3e245eae46 2025-11-09 03:05:33.669413+00:00 -------------------------------------------------------------------------------- Name : bind Product : Fedora 43 Version : 9.18.41 Release : 2.fc43 URL : https://www.isc.org/bind/ Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Fix dual-signed domains verification, when one of algorithms is not supported. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 31 2025 Petr Men\u0161k - 32:9.18.41-2 - Fix upstream reported regression in recent CVE fix (CVE-2025-8677) - Add upstream dnssec system test testcase for this problem -------------------------------------------------------------------------------- References: [ 1 ] Bug #2413070 - Regression with disabled algorithms after CVE-2025-8677 fixes https://bugzilla.redhat.com/show_bug.cgi?id=2413070 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3e245eae46' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fix for dual-signed domains verification issue in bind on Fedora 43 addresses unsupported algorithms.. Bind DNS,Fedora 43,Security Advisory,Algorithm Fix,Dual-Signed Domains. . Severity: Important. LinuxSecurity.com Team
Moderate: lz4 security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:2575', 'synopsis': 'Moderate: lz4 security update', 'severity': 'Moderate', 'topic': 'An update for lz4 is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The lz4 packages provide support for LZ4, a very fast, lossless compression algorithm that provides compression speeds of 400 MB/s per core and scales with multicore CPUs. It also features an extremely fast decoder that reaches speeds of multiple GB/s per core and typically reaches RAM speed limits on multicore systems.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1954559'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-3520.json:::CVE-2021-3520'], 'references': [], 'publishedAt': '2021-07-22T03:13:55.339818Z', 'rpms': ['lz4-1.8.3-3.el8_4.aarch64.rpm', 'lz4-1.8.3-3.el8_4.src.rpm', 'lz4-1.8.3-3.el8_4.x86_64.rpm', 'lz4-debuginfo-1.8.3-3.el8_4.aarch64.rpm', 'lz4-debuginfo-1.8.3-3.el8_4.i686.rpm', 'lz4-debuginfo-1.8.3-3.el8_4.x86_64.rpm', 'lz4-debugsource-1.8.3-3.el8_4.aarch64.rpm', 'lz4-debugsource-1.8.3-3.el8_4.i686.rpm', 'lz4-debugsource-1.8.3-3.el8_4.x86_64.rpm', 'lz4-devel-1.8.3-3.el8_4.aarch64.rpm', 'lz4-devel-1.8.3-3.el8_4.i686.rpm', 'lz4-devel-1.8.3-3.el8_4.x86_64.rpm', 'lz4-libs-1.8.3-3.el8_4.aarch64.rpm', 'lz4-libs-1.8.3-3.el8_4.i686.rpm', 'lz4-libs-1.8.3-3.el8_4.x86_64.rpm', 'lz4-libs-debuginfo-1.8.3-3.el8_4.aarch64.rpm', 'lz4-libs-debuginfo-1.8.3-3.el8_4.i686.rpm', 'lz4-libs-debuginfo-1.8.3-3.el8_4.x86_64.rpm']}\. An update for lz4 on RockyLinux 8 has been issued to mitigate moderate security vulnerabilities. Discover more details.. lz4 Security Update, Rocky Linux 8, Security Patch, Moderate Impact. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.