Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 139 articles for you...
87

Debian PDNS Recursor Critical Denial Of Service Issues DSA-6369-1

Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6369-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 25, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pdns-recursor CVE ID : CVE-2026-33612 CVE-2026-40012 CVE-2026-42005 CVE-2026-42387 CVE-2026-42388 CVE-2026-42390 CVE-2026-52690 Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. For the stable distribution (trixie), these problems have been fixed in version 5.2.11-0+deb13u1. We recommend that you upgrade your pdns-recursor packages. For the detailed security status of pdns-recursor please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pdns-recursor Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple vulnerabilities in PDNS Recursor fixed in Debian Trixie to prevent denial of service and more. Upgrade recommended.. Debian PDNS Recursor Denial of Service Information Disclosure Cache Poisoning. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 Critical Debian
87

Debian DSA-6264-1 Dnsmasq Important Denial of Service CVE-2026-2291

Multiple security vulnerabilities have been discovered in Dnsmasq, a lightweight DNS forwarder and DHCP server, which could result in cache poisoning, bypass of security controls, denial of service or local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6264-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 11, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dnsmasq CVE ID : CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 Multiple security vulnerabilities have been discovered in Dnsmasq, a lightweight DNS forwarder and DHCP server, which could result in cache poisoning, bypass of security controls, denial of service or local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 2.90-4~deb12u2. For the stable distribution (trixie), these problems have been fixed in version 2.91-1+deb13u1. We recommend that you upgrade your dnsmasq packages. For the detailed security status of dnsmasq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dnsmasq Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Discover critical vulnerabilities in dnsmasq affecting Debian distributions and learn how to secure your systems promptly.. dnsmasq security update, Debian dnsmasq vulnerabilities, security advisory dnsmasq. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 11, 2026 Important Debian
100

SUSE: bind Important Security Update for Cache Poisoning 2026:20085-1

An update that solves three vulnerabilities and has one fix can now be installed.. # Security update for bind Announcement ID: SUSE-SU-2026:20085-1 Release Date: 2026-01-15T10:43:49Z Rating: important References: * bsc#1230649 * bsc#1252378 * bsc#1252379 * bsc#1252380 Cross-References: * CVE-2025-40778 * CVE-2025-40780 * CVE-2025-8677 CVSS scores: * CVE-2025-40778 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2025-40778 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40778 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40780 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2025-40780 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40780 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-8677 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-8677 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-8677 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for bind fixes the following issues: * Upgrade to release 9.20.15 Security Fixes: * CVE-2025-40778: Fixed cache poisoning attacks with unsolicited RRs (bsc#1252379) * CVE-2025-40780: Fixed cache poisoning due to weak PRNG (bsc#1252380) * CVE-2025-8677: Fixed resource exhaustion via malformed DNSKEY handling (bsc#1252378) New Features: * Add dnssec-policy keys configuration check to named-checkconf. * Add a new option `manual-mode` to dnssec-policy. * Add a new option `servfail- until-ready` to response-policy zones. * Support for parsing HHIT and BRID records has been added. * Support for parsing DSYNC records has beenadded. Removed Features: * Deprecate the `tkey-gssapi-credential` statement. * Obsolete the `tkey-domain` statement. Feature Changes: * Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1, and DS digest type 1. Bug Fixes: * Missing DNSSEC information when CD bit is set in query. * rndc sign during ZSK rollover will now replace signatures. * Use signer name when disabling DNSSEC algorithms. * Preserve cache when reload fails and reload the server again. * Prevent spurious SERVFAILs for certain 0-TTL resource records. * Fix unexpected termination if catalog-zones had undefined `default-primaries`. * Stale RRsets in a CNAME chain were not always refreshed. * Add RPZ extended DNS error for zones with a CNAME override policy configured. * Fix dig +keepopen option. * Log dropped or slipped responses in the query-errors category. * Fix synth-from-dnssec not working in some scenarios. * Clean enough memory when adding new ADB names/entries under memory pressure. * Prevent spurious validation failures. * Ensure file descriptors 0-2 are in use before using libuv [bsc#1230649] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-144=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-144=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * bind-modules-perl-debuginfo-9.20.15-160000.1.1 * bind-modules-sqlite3-9.20.15-160000.1.1 * bind-utils-9.20.15-160000.1.1 * bind-modules-mysql-debuginfo-9.20.15-160000.1.1 * bind-modules-generic-9.20.15-160000.1.1 * bind-9.20.15-160000.1.1 * bind-debugsource-9.20.15-160000.1.1 * bind-modules-mysql-9.20.15-160000.1.1 * bind-modules-generic-debuginfo-9.20.15-160000.1.1 * bind-utils-debuginfo-9.20.15-160000.1.1 *bind-modules-ldap-debuginfo-9.20.15-160000.1.1 * bind-modules-perl-9.20.15-160000.1.1 * bind-debuginfo-9.20.15-160000.1.1 * bind-modules-ldap-9.20.15-160000.1.1 * bind-modules-sqlite3-debuginfo-9.20.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * bind-doc-9.20.15-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * bind-modules-perl-debuginfo-9.20.15-160000.1.1 * bind-modules-sqlite3-9.20.15-160000.1.1 * bind-utils-9.20.15-160000.1.1 * bind-modules-mysql-debuginfo-9.20.15-160000.1.1 * bind-modules-generic-9.20.15-160000.1.1 * bind-9.20.15-160000.1.1 * bind-debugsource-9.20.15-160000.1.1 * bind-modules-mysql-9.20.15-160000.1.1 * bind-modules-generic-debuginfo-9.20.15-160000.1.1 * bind-utils-debuginfo-9.20.15-160000.1.1 * bind-modules-ldap-debuginfo-9.20.15-160000.1.1 * bind-modules-perl-9.20.15-160000.1.1 * bind-debuginfo-9.20.15-160000.1.1 * bind-modules-ldap-9.20.15-160000.1.1 * bind-modules-sqlite3-debuginfo-9.20.15-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * bind-doc-9.20.15-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40778.html * https://www.suse.com/security/cve/CVE-2025-40780.html * https://www.suse.com/security/cve/CVE-2025-8677.html * https://bugzilla.suse.com/show_bug.cgi?id=1230649 * https://bugzilla.suse.com/show_bug.cgi?id=1252378 * https://bugzilla.suse.com/show_bug.cgi?id=1252379 * https://bugzilla.suse.com/show_bug.cgi?id=1252380 . Find detailed information about a SUSE security advisory for bind addressing multiple critical issues regarding cache management.. SUSE Linux, bind security update, cache poisoning, DNS security, important vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 20, 2026 Important SuSE
202

openSUSE Leap 16.0: Major Security Updates Addressing BIND CVE-2025-40778

An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for bind ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20039-1 Rating: important References: * bsc#1230649 * bsc#1252378 * bsc#1252379 * bsc#1252380 Cross-References: * CVE-2025-40778 * CVE-2025-40780 * CVE-2025-8677 CVSS scores: * CVE-2025-40778 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40778 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2025-40780 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40780 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2025-8677 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-8677 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for bind fixes the following issues: - Upgrade to release 9.20.15 Security Fixes: * CVE-2025-40778: Fixed cache poisoning attacks with unsolicited RRs (bsc#1252379) * CVE-2025-40780: Fixed cache poisoning due to weak PRNG (bsc#1252380) * CVE-2025-8677: Fixed resource exhaustion via malformed DNSKEY handling (bsc#1252378) New Features: * Add dnssec-policy keys configuration check to named-checkconf. * Add a new option `manual-mode` to dnssec-policy. * Add a new option `servfail-until-ready` to response-policy zones. * Support for parsing HHIT and BRID records has been added. * Support for parsing DSYNC records has been added. Removed Features: * Deprecate the `tkey-gssapi-credential` statement. * Obsolete the `tkey-domain` statement. Feature Changes: * Add deprecation warnings for RSASHA1, RSASHA1-NSEC3SHA1, and DS digest type 1. Bug Fixes: * Missing DNSSEC information when CD bit is set in query. * rndc sign during ZSK rollover will now replace signatures. * Use signer name when disabling DNSSEC algorithms. * Preserve cache when reload fails and reload the server again. * Prevent spurious SERVFAILs for certain 0-TTL resource records. * Fix unexpected termination if catalog-zones had undefined `default-primaries`. * Stale RRsets in a CNAME chain were not always refreshed. * Add RPZ extended DNS error for zones with a CNAME override policy configured. * Fix dig +keepopen option. * Log dropped or slipped responses in the query-errors category. * Fix synth-from-dnssec not working in some scenarios. * Clean enough memory when adding new ADB names/entries under memory pressure. * Prevent spurious validation failures. * Ensure file descriptors 0-2 are in use before using libuv [bsc#1230649] Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-144=1 Package List: - openSUSE Leap 16.0: bind-9.20.15-160000.1.1 bind-doc-9.20.15-160000.1.1 bind-modules-bdbhpt-9.20.15-160000.1.1 bind-modules-generic-9.20.15-160000.1.1 bind-modules-ldap-9.20.15-160000.1.1 bind-modules-mysql-9.20.15-160000.1.1 bind-modules-perl-9.20.15-160000.1.1 bind-modules-sqlite3-9.20.15-160000.1.1 bind-utils-9.20.15-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-40778.html * https://www.suse.com/security/cve/CVE-2025-40780.html * https://www.suse.com/security/cve/CVE-2025-8677.html . A security update for openSUSE bind addresses critical cache poisoning and resource exhaustion issues with CVE-2025-40778.. openSUSE security, bind update, CVE-2025-40780, DNS vulnerabilities, important security fixes. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jan 17, 2026 Important OpenSUSE
87

Debian: Unbound Critical Cache Poisoning Fix DSA-6071-1 CVE-2025-11411

It was discovered that incorrect handling of promiscuous NS RRSets in Unbound, a validating, recursive, caching DNS resolver, could result in cache poisoning. For the stable distribution (trixie), this problem has been fixed in version 1.22.0-2+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6071-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 04, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : unbound CVE ID : CVE-2025-11411 It was discovered that incorrect handling of promiscuous NS RRSets in Unbound, a validating, recursive, caching DNS resolver, could result in cache poisoning. For the stable distribution (trixie), this problem has been fixed in version 1.22.0-2+deb13u1. We recommend that you upgrade your unbound packages. For the detailed security status of unbound please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/unbound Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Unbound's cache poisoning issue fixed in Debian 1.22.0-2+deb13u1 update to prevent potential security risks.. Unbound Security Patch, Debian Advisory, DNS Resolver Update, Cache Poisoning Fix, Unbound Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2025 Critical Debian
217

Oracle Linux 9: ELSA-2025-21110 BIND Important Cache Poisoning Fix

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-21110 http://linux.oracle.com/errata/ELSA-2025-21110.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bind-9.16.23-34.0.1.el9_7.1.x86_64.rpm bind-chroot-9.16.23-34.0.1.el9_7.1.x86_64.rpm bind-devel-9.16.23-34.0.1.el9_7.1.i686.rpm bind-devel-9.16.23-34.0.1.el9_7.1.x86_64.rpm bind-dnssec-doc-9.16.23-34.0.1.el9_7.1.noarch.rpm bind-dnssec-utils-9.16.23-34.0.1.el9_7.1.x86_64.rpm bind-doc-9.16.23-34.0.1.el9_7.1.noarch.rpm bind-libs-9.16.23-34.0.1.el9_7.1.i686.rpm bind-libs-9.16.23-34.0.1.el9_7.1.x86_64.rpm bind-license-9.16.23-34.0.1.el9_7.1.noarch.rpm bind-utils-9.16.23-34.0.1.el9_7.1.x86_64.rpm python3-bind-9.16.23-34.0.1.el9_7.1.noarch.rpm aarch64: bind-9.16.23-34.0.1.el9_7.1.aarch64.rpm bind-chroot-9.16.23-34.0.1.el9_7.1.aarch64.rpm bind-devel-9.16.23-34.0.1.el9_7.1.aarch64.rpm bind-dnssec-doc-9.16.23-34.0.1.el9_7.1.noarch.rpm bind-dnssec-utils-9.16.23-34.0.1.el9_7.1.aarch64.rpm bind-doc-9.16.23-34.0.1.el9_7.1.noarch.rpm bind-libs-9.16.23-34.0.1.el9_7.1.aarch64.rpm bind-license-9.16.23-34.0.1.el9_7.1.noarch.rpm bind-utils-9.16.23-34.0.1.el9_7.1.aarch64.rpm python3-bind-9.16.23-34.0.1.el9_7.1.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/bind-9.16.23-34.0.1.el9_7.1.src.rpm Related CVEs: CVE-2025-40778 CVE-2025-40780 Description of changes: [32:9.16.23-34.0.1.1] - Fix warning when changing device file permissions [Orabug: 36518580] [32:9.16.23-34.1] - Prevent cache poisoning due to weak PRNG (CVE-2025-40780) - Replace downstream fixes with upstream changes - Address various spoofing attacks (CVE-2025-40778) [32:9.16.23-34] - Fix failures in idna system test (RHEL-66172) [32:9.16.23-33] - logrotate: skip if empty and remove old variants (RHEL-113942) [32:9.16.23-32] - Decode IDN names on input in all situations in utilities(RHEL-66172) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Significant updates for Oracle Linux 9 bind to address security issues and improve system integrity.. Oracle Linux Security, BIND Updates, Important Fixes, Cache Poisoning, Spoofing Attacks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 26, 2025 Important Oracle
100

UBUNTU: Critical Spoofing Vulnerability Mitigation 2025:3333-2

* bsc#1252379 * bsc#1252380 Cross-References: * CVE-2025-40778 . # Security update for bind Announcement ID: SUSE-SU-2025:4222-1 Release Date: 2025-11-25T08:54:07Z Rating: important References: * bsc#1252379 * bsc#1252380 Cross-References: * CVE-2025-40778 * CVE-2025-40780 CVSS scores: * CVE-2025-40778 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2025-40778 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40778 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40780 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2025-40780 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-40780 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Manager Client Tools for SLE Micro 5 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves two vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2025-40778: Address various spoofing attacks (bsc#1252379). * CVE-2025-40780: Cache-poisoning due to weak pseudo-random number generator (bsc#1252380). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2025-4222=1 * SUSE Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2025-4222=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * libisc1606-9.16.6-150000.12.85.1 * libbind9-1600-debuginfo-9.16.6-150000.12.85.1 * libisccc1600-debuginfo-9.16.6-150000.12.85.1 * bind-debugsource-9.16.6-150000.12.85.1 * libisccfg1600-9.16.6-150000.12.85.1 * libns1604-debuginfo-9.16.6-150000.12.85.1 * libirs1601-9.16.6-150000.12.85.1 * libisc1606-debuginfo-9.16.6-150000.12.85.1 * libirs1601-debuginfo-9.16.6-150000.12.85.1 * libisccfg1600-debuginfo-9.16.6-150000.12.85.1 * libns1604-9.16.6-150000.12.85.1 * bind-utils-9.16.6-150000.12.85.1 * libdns1605-debuginfo-9.16.6-150000.12.85.1 * bind-debuginfo-9.16.6-150000.12.85.1 * libisccc1600-9.16.6-150000.12.85.1 * libbind9-1600-9.16.6-150000.12.85.1 * libdns1605-9.16.6-150000.12.85.1 * bind-utils-debuginfo-9.16.6-150000.12.85.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.85.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64 s390x x86_64) * libisc1606-9.16.6-150000.12.85.1 * libisccfg1600-9.16.6-150000.12.85.1 * libns1604-debuginfo-9.16.6-150000.12.85.1 * libirs1601-9.16.6-150000.12.85.1 * libns1604-9.16.6-150000.12.85.1 * bind-utils-9.16.6-150000.12.85.1 * libisccc1600-9.16.6-150000.12.85.1 * libbind9-1600-9.16.6-150000.12.85.1 * libdns1605-9.16.6-150000.12.85.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64_ilp32) * libisc1606-64bit-9.16.6-150000.12.85.1 * libirs1601-64bit-9.16.6-150000.12.85.1 * libisccc1600-64bit-9.16.6-150000.12.85.1 * libbind9-1600-64bit-9.16.6-150000.12.85.1 * libisccfg1600-64bit-9.16.6-150000.12.85.1 * libdns1605-64bit-9.16.6-150000.12.85.1 * SUSE Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.85.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40778.html * https://www.suse.com/security/cve/CVE-2025-40780.html * https://bugzilla.suse.com/show_bug.cgi?id=1252379 * https://bugzilla.suse.com/show_bug.cgi?id=1252380 .Security update for SUSE addressing important vulnerabilities in bind, including spoofing and cache-poisoning threats.. SUSE Linux, bind vulnerabilities, security patch, software update, SUSE advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 25, 2025 Important SuSE
219

Rocky Linux 10 BIND Major Revision Cache Pollution Flaws RLSA-2025-21034

Important: bind security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:21034", "synopsis": "Important: bind security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for bind.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.\n\nSecurity Fix(es):\n\n* bind: Cache poisoning attacks with unsolicited RRs (CVE-2025-40778)\n\n* bind: Cache poisoning due to weak PRNG (CVE-2025-40780)\n\n* bind: Resource exhaustion via malformed DNSKEY handling (CVE-2025-8677)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2405827", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2405827", "description": ""}, {"ticket": "2405829", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2405829", "description": ""}, {"ticket": "2405830", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2405830", "description": ""}], "cves": [{"name": "CVE-2025-40778", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-40778", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N", "cvss3BaseScore": "8.6", "cwe": "CWE-347"}, {"name": "CVE-2025-40780", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-40780", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","cvss3BaseScore": "8.6", "cwe": "CWE-338"}, {"name": "CVE-2025-8677", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-8677", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2025-11-21T18:19:15.687303Z", "rpms": {"Rocky Linux 10": {"nvras": ["bind-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-32:9.18.33-10.el10_1.2.src.rpm", "bind-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-chroot-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-chroot-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-chroot-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-chroot-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-debuginfo-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-debuginfo-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-debuginfo-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-debuginfo-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-debugsource-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-debugsource-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-debugsource-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-debugsource-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-devel-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-devel-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-devel-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-devel-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-dnssec-utils-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-dnssec-utils-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-dnssec-utils-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-dnssec-utils-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-dnssec-utils-debuginfo-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-dnssec-utils-debuginfo-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-dnssec-utils-debuginfo-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-dnssec-utils-debuginfo-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-doc-32:9.18.33-10.el10_1.2.noarch.rpm", "bind-libs-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-libs-32:9.18.33-10.el10_1.2.ppc64le.rpm","bind-libs-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-libs-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-libs-debuginfo-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-libs-debuginfo-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-libs-debuginfo-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-libs-debuginfo-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-license-32:9.18.33-10.el10_1.2.noarch.rpm", "bind-utils-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-utils-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-utils-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-utils-32:9.18.33-10.el10_1.2.x86_64.rpm", "bind-utils-debuginfo-32:9.18.33-10.el10_1.2.aarch64.rpm", "bind-utils-debuginfo-32:9.18.33-10.el10_1.2.ppc64le.rpm", "bind-utils-debuginfo-32:9.18.33-10.el10_1.2.s390x.rpm", "bind-utils-debuginfo-32:9.18.33-10.el10_1.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Bind update resolves important cache poisoning risks on Rocky Linux 10 with multiple CVEs and recommended actions.. bind security update, Rocky Linux, CVE fixes, cache poisoning risks, DNS vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 21, 2025 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200