Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
update to latest upstream release to fix CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-088b60c071 2026-07-04 00:49:17.194874+00:00 -------------------------------------------------------------------------------- Name : pdns-recursor Product : Fedora 44 Version : 5.4.3 Release : 1.fc44 URL : https://powerdns.com Summary : Modern, advanced and high performance recursing/non authoritative name server Description : PowerDNS Recursor is a non authoritative/recursing DNS server. Use this package if you need a dns cache for your network. -------------------------------------------------------------------------------- Update Information: update to latest upstream release to fix CVEs -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Filipe Rosset - 5.4.3-1 - update to 5.4.3 fixes rhbz#2492868 - a bunch of other bugs were fixed and will be backported to all supported Fedora / EPEL versions * Sun Jun 14 2026 Yaakov Selkowitz - 5.4.2-4 - Drop unused openssl-devel-engine dependency * Fri Jun 12 2026 Yaakov Selkowitz - 5.4.2-3 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2438157 - CVE-2025-59023 pdns-recursor: crafted delegations or IP fragments can poison cached delegations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438157 [ 2 ] Bug #2438176 - CVE-2025-59024 pdns-recursor: crafted delegations or IP fragments can poison cached delegations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438176 [ 3 ] Bug #2438180 - CVE-2026-0398 pdns-recursor: crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438180 [ 4 ] Bug #2438184 - CVE-2026-24027 pdns-recursor: craftedzones can lead to increased incoming network traffic [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438184 [ 5 ] Bug #2460825 - CVE-2026-33600 pdns-recursor: NULL pointer dereference in RPZ transfer [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460825 [ 6 ] Bug #2460826 - CVE-2026-33261 pdns-recursor: NULL pointer access in aggressive NSEC(3) cache [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460826 [ 7 ] Bug #2460827 - CVE-2026-33259 pdns-recursor: concurrent modification of RPZ data can lead to denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460827 [ 8 ] Bug #2460828 - CVE-2026-33258 pdns-recursor: crafted zones can cause increased resource usage [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460828 [ 9 ] Bug #2460829 - CVE-2026-33601 pdns-recursor: insufficient validation of ZONEMD record [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460829 [ 10 ] Bug #2493667 - CVE-2026-33612 pdns-recursor: ZoneToCache can poison the cache [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493667 [ 11 ] Bug #2493668 - CVE-2026-40012 pdns-recursor: information about ECS zero scoped answers might leak to clients that use a specific ECS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493668 [ 12 ] Bug #2493669 - CVE-2026-42388 pdns-recursor: missing input validation for catalog zones [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493669 [ 13 ] Bug #2493670 - CVE-2026-42387 pdns-recursor: insufficient input validation in ZoneToCache [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493670 [ 14 ] Bug #2493671 - CVE-2026-42390 pdns-recursor: ZONEMD validation can be bypassed [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493671 [ 15 ] Bug #2493672 - CVE-2026-52690 pdns-recursor: spoofed answers can mark an authoritative non-EDNS capable [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493672 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-088b60c071' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to latest upstream. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-db1ef256e0 2026-04-25 01:21:36.171800+00:00 -------------------------------------------------------------------------------- Name : pdns-recursor Product : Fedora 44 Version : 5.4.0 Release : 1.fc44 URL : https://powerdns.com Summary : Modern, advanced and high performance recursing/non authoritative name server Description : PowerDNS Recursor is a non authoritative/recursing DNS server. Use this package if you need a dns cache for your network. -------------------------------------------------------------------------------- Update Information: Update to latest upstream -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2026 Sander Hoentjen - 5.4.0-1 - Update to latest upstream -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454302 - F44FailsToInstall: pdns-recursor https://bugzilla.redhat.com/show_bug.cgi?id=2454302 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db1ef256e0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 9.21.17 (rhbz#2415843) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) New Features: Add support for Extended DNS Error 9 (Missing DNSKEY).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b31c8d8e83 2026-01-31 17:26:56.329411+00:00 -------------------------------------------------------------------------------- Name : bind9-next Product : Fedora 43 Version : 9.21.17 Release : 1.fc43 URL : https://www.isc.org/bind/ Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Update to 9.21.17 (rhbz#2415843) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) New Features: Add support for Extended DNS Error 9 (Missing DNSKEY). Add support for Extended DNS Error 13 (Cached Error). Add support for Generalized DNS Notifications. Features Changes: Add more information to the rndc recursing output about fetches. Enforce bounds of multiple configuration options. Bug Fixes: Fix inbound IXFR performance regression. Make DNSSEC key rollovers more robust. Fix a catalog zone issue, where member zones could fail to load. Fix slow speed when signing a large delegation zone with NSEC3 opt-out. Reconfiguring an NSEC3 opt-out zone to NSEC caused the zone to be invalid. Fix a possible catalog zone issue during reconfiguration. Fix the charts in the statisticschannel. https://downloads.isc.org/isc/bind9/9.21.17/doc/arm/html/notes.html#notes-for- bind-9-21-17 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 22 2026 Petr Men\u0161k - 32:9.21.17-1 - Update to 9.21.17 (rhbz#2415843) * Thu Jan 22 2026 Petr Men\u0161k - 32:9.21.16-2 - Fix build for RHEL, disable JEMALLOC there * Thu Jan 22 2026 Petr Men\u0161k - 32:9.21.16-1 - Update to 9.21.16 (rhbz#2415843) * Thu Jan 22 2026 Petr Men\u0161k - 32:9.21.15-2 - Use dns-root-data package for hints source * Thu Jan 22 2026 Petr Men\u0161k - 32:9.21.15-1 - Update to 9.21.15 (rhbz#2415843) * Thu Jan 22 2026 Petr Men\u0161k - 32:9.21.14-3 - Fix running SYSTEMTEST during build -------------------------------------------------------------------------------- References: [ 1 ] Bug #2415843 - bind9-next-9.21.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=2415843 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b31c8d8e83' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 updates bind9-next for security fixes including Critical CVE-2025-13878 with new features and enhancements.. bind9-next, Fedora 43, security fix, DNS server. . Severity: Important. LinuxSecurity.com Team
Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-567ff6c687 2026-01-27 05:36:35.122886+00:00 -------------------------------------------------------------------------------- Name : bind Product : Fedora 43 Version : 9.18.44 Release : 1.fc43 URL : https://www.isc.org/bind/ Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. -------------------------------------------------------------------------------- Update Information: Update to 9.18.44 (rhbz#2431609) Security Fixes: Fix incorrect length checks for BRID and HHIT records. (CVE-2025-13878) Bug Fixes: Allow glue in delegations with QTYPE=ANY. Reconfiguring an NSEC3 opt-out zone to NSEC caused the zone to be invalid. https://downloads.isc.org/isc/bind9/9.18.44/doc/arm/html/notes.html#notes-for- bind-9-18-44 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 22 2026 Petr Men\u0161k - 32:9.18.44-1 - Update to 9.18.44 (rhbz#2431609) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2431609 - bind-9.18.44 is available https://bugzilla.redhat.com/show_bug.cgi?id=2431609 [ 2 ] Bug #2431925 - CVE-2025-13878 bind: bind: Denial of Service via corrupt or malicious record [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431925 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-567ff6c687' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical security advisory for Fedora 43's BIND 9.18.44 addresses denial of service risk from incorrect length checks.. Fedora security advisory,BIND update,DNS server fixes,security risk,Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2023-3341 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5504-1
Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2023-2828 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5439-1
An update for dnsmasq is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: dnsmasq security update Advisory ID: RHSA-2021:0151-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0151 Issue date: 2021-01-19 CVE Names: CVE-2020-25681 CVE-2020-25682 CVE-2020-25683 CVE-2020-25684 CVE-2020-25685 CVE-2020-25686 CVE-2020-25687 ==================================================================== 1. Summary: An update for dnsmasq is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.2) - aarch64, ppc64le, s390x, x86_64 3. Description: The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server. Security Fix(es): * dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled (CVE-2020-25681) * dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled (CVE-2020-25682) * dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled (CVE-2020-25683) * dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25684) * dnsmasq: loose query name check inreply_query() makes forging replies easier for an off-path attacker (CVE-2020-25685) * dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker (CVE-2020-25686) * dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled (CVE-2020-25687) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1881875 - CVE-2020-25681 dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled 1882014 - CVE-2020-25682 dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled 1882018 - CVE-2020-25683 dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled 1889686 - CVE-2020-25684 dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker 1889688 - CVE-2020-25685 dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker 1890125 - CVE-2020-25686 dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker 1891568 - CVE-2020-25687 dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.2): Source: dnsmasq-2.79-11.el8_2.2.src.rpm aarch64: dnsmasq-2.79-11.el8_2.2.aarch64.rpm dnsmasq-debuginfo-2.79-11.el8_2.2.aarch64.rpm dnsmasq-debugsource-2.79-11.el8_2.2.aarch64.rpm dnsmasq-utils-2.79-11.el8_2.2.aarch64.rpm dnsmasq-utils-debuginfo-2.79-11.el8_2.2.aarch64.rpm ppc64le: dnsmasq-2.79-11.el8_2.2.ppc64le.rpm dnsmasq-debuginfo-2.79-11.el8_2.2.ppc64le.rpm dnsmasq-debugsource-2.79-11.el8_2.2.ppc64le.rpm dnsmasq-utils-2.79-11.el8_2.2.ppc64le.rpm dnsmasq-utils-debuginfo-2.79-11.el8_2.2.ppc64le.rpm s390x: dnsmasq-2.79-11.el8_2.2.s390x.rpm dnsmasq-debuginfo-2.79-11.el8_2.2.s390x.rpm dnsmasq-debugsource-2.79-11.el8_2.2.s390x.rpm dnsmasq-utils-2.79-11.el8_2.2.s390x.rpm dnsmasq-utils-debuginfo-2.79-11.el8_2.2.s390x.rpm x86_64: dnsmasq-2.79-11.el8_2.2.x86_64.rpm dnsmasq-debuginfo-2.79-11.el8_2.2.x86_64.rpm dnsmasq-debugsource-2.79-11.el8_2.2.x86_64.rpm dnsmasq-utils-2.79-11.el8_2.2.x86_64.rpm dnsmasq-utils-debuginfo-2.79-11.el8_2.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-25681 https://access.redhat.com/security/cve/CVE-2020-25682 https://access.redhat.com/security/cve/CVE-2020-25683 https://access.redhat.com/security/cve/CVE-2020-25684 https://access.redhat.com/security/cve/CVE-2020-25685 https://access.redhat.com/security/cve/CVE-2020-25686 https://access.redhat.com/security/cve/CVE-2020-25687 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/RHSB-2021-001 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYAbgy9zjgjWX9erEAQhsJg/7BiUPmYio6D87XkN9fcWf2VYynkHDOI1k 43jB7EnfLvUh/UrJSi3n3YH8a0eibMke1heXDUIuTBbv0BX5qi7QuOzmqD8bEsMq esRcEyG2BGjVZ9eC5/Enm+L2j/lOUH8EEFH3O2tqEa4/U8oD3HB5ejofQo79uLwE mGGIIc8pBzQDqGb/7ROt418VCwed5716OVmn5PV/A7zpbXf2Wg8AYBkuzm3aE/VS +Jd7JIpFXaJwbszRZ2JJwXs4sKrxM49FTMJ0TjYZgwo6waLML9Fv43f87Tz9n4Wu B56lH8OQZmJCH5tbbsrzCWa25cvf057UfBhQqj5qqsPPUL/I/oh4dEGQs58vUz+Y bnuhDQqhjfa6FbBLyAMAHJf5l6X62ZnkIIDc3xPPsiTHdtuggOLZxQiXvm9QkKuI LRReXUJVeLs2sq2SxXYHb9GqcCOV4M5K9+NpS4w/ICikKzd2RkCfVABymz2sVm7K tGW3OsTmkhWpyAczYqp8zXm9abK+kwwQqkuQeb3JBQ+WInwSab63sT/nggDH/oWM IqMb26QypNNr2cpZ/DB2HooGehSeLXNmAPrbeuIKowuKrCL0xRPTb9db2yXqttTS WUNnKM3h66Ju+Gzzk+JhtoJl3lomGIgiT1c+QXvPC9B6lmFojx8lZKsxsQ1Qkudd rwOB2/q5hRY=vAYb -----END PGP SIGNATURE----- -- RHSA-announce mailing list
- Update to 4.3.5 Release notes: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html Security Advisory: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-51ca2615fe 2020-10-23 22:01:02.263670 --------------------------------------------------------------------------------Name : pdns-recursor Product : Fedora 33 Version : 4.3.5 Release : 1.fc33 URL : https://www.powerdns.com/ Summary : Modern, advanced and high performance recursing/non authoritative name server Description : PowerDNS Recursor is a non authoritative/recursing DNS server. Use this package if you need a dns cache for your network. --------------------------------------------------------------------------------Update Information: - Update to 4.3.5 Release notes: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html Security Advisory: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-07.html --------------------------------------------------------------------------------ChangeLog: * Mon Oct 19 2020 Morten Stevens - 4.3.5-1 - Update to 4.3.5 * Thu Sep 24 2020 Adrian Reber - 4.3.4-2 - Rebuilt for protobuf 3.13 --------------------------------------------------------------------------------References: [ 1 ] Bug #1887753 - pdns-recursor-4.3.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1887753 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-51ca2615fe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.