Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
An update that solves 18 vulnerabilities can now be installed.. # Security update for dnsdist Announcement ID: SUSE-SU-2026:22319-1 Release Date: 2026-06-22T14:30:36Z Rating: moderate References: * bsc#1261236 * bsc#1261237 * bsc#1261238 * bsc#1261239 * bsc#1261240 * bsc#1261241 * bsc#1261243 * bsc#1262536 * bsc#1262537 * bsc#1262538 * bsc#1262539 * bsc#1262540 * bsc#1262541 * bsc#1262542 * bsc#1262543 * bsc#1262544 * bsc#1262545 * bsc#1262546 Cross-References: * CVE-2026-0396 * CVE-2026-0397 * CVE-2026-24028 * CVE-2026-24029 * CVE-2026-24030 * CVE-2026-27853 * CVE-2026-27854 * CVE-2026-33254 * CVE-2026-33257 * CVE-2026-33260 * CVE-2026-33593 * CVE-2026-33594 * CVE-2026-33595 * CVE-2026-33596 * CVE-2026-33597 * CVE-2026-33598 * CVE-2026-33599 * CVE-2026-33602 CVSS scores: * CVE-2026-0396 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-0396 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0397 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-0397 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-24028 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-24029 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24029 ( SUSE ): 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24030 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24030 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27853 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27854 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33254 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33260 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33593 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33594 ( NVD ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33595 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33595 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33596 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33596 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33597 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33598 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-33598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33599 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33599 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33602 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33602 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for dnsdist fixes the following issues * CVE-2026-0396: crafted DNS queries can allow to inject HTML content (bsc#1261236). * CVE-2026-0397: CORS misconfiguration can lead to information disclosure (bsc#1261237). * CVE-2026-24028: crafted DNS response packet can lead to an out-of-bounds read (bsc#1261238). * CVE-2026-24029: HTTPS ACL bypass can allow clients to send DoH queries (bsc#1261239). * CVE-2026-24030: allocating too much memory while processing DNS can result in a denial of service (bsc#1261240). * CVE-2026-27853: crafted DNS responses can lead to an out-of-bounds write (bsc#1261241). * CVE-2026-27854: crafted DNS queries can be used to trigger a use-after-free (bsc#1261243). * CVE-2026-33254: Resource exhaustion via DoQ/DoH3 connections (bsc#1262538). * CVE-2026-33257:Insufficient input validation of internal webserver (bsc#1262536). * CVE-2026-33260: Insufficient input validation of internal webserver (bsc#1262537). * CVE-2026-33593: Denial of service via crafted DNSCrypt query (bsc#1262546). * CVE-2026-33594: Outgoing DoH excessive memory allocation (bsc#1262545). * CVE-2026-33595: DoQ/DoH3 excessive memory allocation (bsc#1262544). * CVE-2026-33596: TCP backend stream ID overflow (bsc#1262543). * CVE-2026-33597: PRSD detection denial of service (bsc#1262542). * CVE-2026-33598: Out-of-bounds read in cache inspection via Lua (bsc#1262541). * CVE-2026-33599: Out-of-bounds read in service discovery (bsc#1262540). * CVE-2026-33602: Off-by-one access when processing crafted UDP responses (bsc#1262539). Changes for dnsdist: * Updated to 1.9.13 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1027=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1027=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dnsdist-1.9.13-160000.1.1 * dnsdist-debugsource-1.9.13-160000.1.1 * dnsdist-debuginfo-1.9.13-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dnsdist-1.9.13-160000.1.1 * dnsdist-debugsource-1.9.13-160000.1.1 * dnsdist-debuginfo-1.9.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0396.html * https://www.suse.com/security/cve/CVE-2026-0397.html * https://www.suse.com/security/cve/CVE-2026-24028.html * https://www.suse.com/security/cve/CVE-2026-24029.html * https://www.suse.com/security/cve/CVE-2026-24030.html * https://www.suse.com/security/cve/CVE-2026-27853.html * https://www.suse.com/security/cve/CVE-2026-27854.html * https://www.suse.com/security/cve/CVE-2026-33254.html * https://www.suse.com/security/cve/CVE-2026-33257.html * https://www.suse.com/security/cve/CVE-2026-33260.html * https://www.suse.com/security/cve/CVE-2026-33593.html * https://www.suse.com/security/cve/CVE-2026-33594.html * https://www.suse.com/security/cve/CVE-2026-33595.html * https://www.suse.com/security/cve/CVE-2026-33596.html * https://www.suse.com/security/cve/CVE-2026-33597.html * https://www.suse.com/security/cve/CVE-2026-33598.html * https://www.suse.com/security/cve/CVE-2026-33599.html * https://www.suse.com/security/cve/CVE-2026-33602.html * https://bugzilla.suse.com/show_bug.cgi?id=1261236 * https://bugzilla.suse.com/show_bug.cgi?id=1261237 * https://bugzilla.suse.com/show_bug.cgi?id=1261238 * https://bugzilla.suse.com/show_bug.cgi?id=1261239 * https://bugzilla.suse.com/show_bug.cgi?id=1261240 * https://bugzilla.suse.com/show_bug.cgi?id=1261241 * https://bugzilla.suse.com/show_bug.cgi?id=1261243 * https://bugzilla.suse.com/show_bug.cgi?id=1262536 * https://bugzilla.suse.com/show_bug.cgi?id=1262537 * https://bugzilla.suse.com/show_bug.cgi?id=1262538 * https://bugzilla.suse.com/show_bug.cgi?id=1262539 * https://bugzilla.suse.com/show_bug.cgi?id=1262540 * https://bugzilla.suse.com/show_bug.cgi?id=1262541 * https://bugzilla.suse.com/show_bug.cgi?id=1262542 * https://bugzilla.suse.com/show_bug.cgi?id=1262543 * https://bugzilla.suse.com/show_bug.cgi?id=1262544 * https://bugzilla.suse.com/show_bug.cgi?id=1262545 * https://bugzilla.suse.com/show_bug.cgi?id=1262546 . An important SUSE security advisory for dnsdist patching 18 issues including DoS and disclosure risks effectively.. dnsdist security fix, SUSE server update, patch installation advisory. . Severity: moderate. LinuxSecurity.com Team
An update that solves 18 vulnerabilities and has 18 bug fixes can now be installed.. openSUSE security update: security update for dnsdist ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21015-1 Rating: moderate References: * bsc#1261236 * bsc#1261237 * bsc#1261238 * bsc#1261239 * bsc#1261240 * bsc#1261241 * bsc#1261243 * bsc#1262536 * bsc#1262537 * bsc#1262538 * bsc#1262539 * bsc#1262540 * bsc#1262541 * bsc#1262542 * bsc#1262543 * bsc#1262544 * bsc#1262545 * bsc#1262546 Cross-References: * CVE-2026-0396 * CVE-2026-0397 * CVE-2026-24028 * CVE-2026-24029 * CVE-2026-24030 * CVE-2026-27853 * CVE-2026-27854 * CVE-2026-33254 * CVE-2026-33257 * CVE-2026-33260 * CVE-2026-33593 * CVE-2026-33594 * CVE-2026-33595 * CVE-2026-33596 * CVE-2026-33597 * CVE-2026-33598 * CVE-2026-33599 * CVE-2026-33602 CVSS scores: * CVE-2026-0396 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-0397 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-24028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24029 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24030 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27853 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27854 ( SUSE ): 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33257 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 18 vulnerabilities and has 18 bug fixes can now be installed. Description: This update for dnsdist fixes the following issues - CVE-2026-0396: crafted DNS queries can allow to inject HTML content (bsc#1261236). - CVE-2026-0397: CORS misconfiguration can lead to information disclosure (bsc#1261237). - CVE-2026-24028: crafted DNS response packet can lead to an out-of-bounds read (bsc#1261238). - CVE-2026-24029: HTTPS ACL bypass can allow clients to send DoH queries (bsc#1261239). - CVE-2026-24030: allocating too much memory while processing DNS can result in a denial of service (bsc#1261240). - CVE-2026-27853: crafted DNS responses can lead to an out-of-bounds write (bsc#1261241). - CVE-2026-27854: crafted DNS queries can be used to trigger a use-after-free (bsc#1261243). - CVE-2026-33254: Resource exhaustion via DoQ/DoH3 connections (bsc#1262538). - CVE-2026-33257: Insufficient input validation of internal webserver (bsc#1262536). - CVE-2026-33260: Insufficient input validation of internal webserver (bsc#1262537). - CVE-2026-33593: Denial of service via crafted DNSCrypt query (bsc#1262546). - CVE-2026-33594: Outgoing DoH excessive memory allocation (bsc#1262545). - CVE-2026-33595: DoQ/DoH3 excessive memory allocation (bsc#1262544). - CVE-2026-33596: TCP backend stream ID overflow (bsc#1262543). - CVE-2026-33597: PRSD detection denial of service (bsc#1262542). - CVE-2026-33598: Out-of-bounds read in cache inspection via Lua (bsc#1262541). - CVE-2026-33599: Out-of-bounds read in service discovery (bsc#1262540). - CVE-2026-33602: Off-by-one access when processing crafted UDP responses(bsc#1262539). Changes for dnsdist: - Updated to 1.9.13 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1027=1 Package List: - openSUSE Leap 16.0: dnsdist-1.9.13-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-0396.html * https://www.suse.com/security/cve/CVE-2026-0397.html * https://www.suse.com/security/cve/CVE-2026-24028.html * https://www.suse.com/security/cve/CVE-2026-24029.html * https://www.suse.com/security/cve/CVE-2026-24030.html * https://www.suse.com/security/cve/CVE-2026-27853.html * https://www.suse.com/security/cve/CVE-2026-27854.html * https://www.suse.com/security/cve/CVE-2026-33254.html * https://www.suse.com/security/cve/CVE-2026-33257.html * https://www.suse.com/security/cve/CVE-2026-33260.html * https://www.suse.com/security/cve/CVE-2026-33593.html * https://www.suse.com/security/cve/CVE-2026-33594.html * https://www.suse.com/security/cve/CVE-2026-33595.html * https://www.suse.com/security/cve/CVE-2026-33596.html * https://www.suse.com/security/cve/CVE-2026-33597.html * https://www.suse.com/security/cve/CVE-2026-33598.html * https://www.suse.com/security/cve/CVE-2026-33599.html * https://www.suse.com/security/cve/CVE-2026-33602.html . This security advisory addresses 18 vulnerabilities and bug fixes in dnsdist for openSUSE, emphasizing moderate risks.. dnsdist update, openSUSE patch, moderate security risk, information disclosure, memory issues. . Severity: moderate. LinuxSecurity.com Team
Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. For the stable distribution (trixie), these problems have been fixed in version 1.9.15-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6367-1
Bug Fixes: CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default CVE-2026-33257: An attacker can send a web request that causes unlimited memory. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-51cdd1292b 2026-06-15 00:48:35.285145+00:00 -------------------------------------------------------------------------------- Name : dnsdist Product : Fedora 44 Version : 2.0.6 Release : 1.fc44 URL : https://dnsdist.org Summary : Highly DNS-, DoS- and abuse-aware loadbalancer Description : dnsdist is a highly DNS-, DoS- and abuse-aware loadbalancer. Its goal in life is to route traffic to the best server, delivering top performance to legitimate users while shunting or blocking abusive traffic. -------------------------------------------------------------------------------- Update Information: Bug Fixes: CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default CVE-2026-33257: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default CVE-2026-33260: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default CVE-2026-33593: A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query CVE-2026-33595: A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.DOQ and DoH3 are disabled by default CVE-2026-33596: A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend CVE-2026-33597: A crafted query containing an invalid DNS label can prevent the PRSD detection algorithm executed via DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI from being executed CVE-2026-33598: A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache CVE-2026-33599: A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default CVE-2026-33602: A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service CVE-2026-33594: A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection. Outgoing DoH is disabled by default -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 5 2026 Filipe Rosset - 2.0.6-1 - update to 2.0.6 fixes rhbz#2460540 * Fri May 29 2026 Miroslav Suchý - 2.0.3-2 - rebuild for https://fedoraproject.org/wiki/Changes/Protobuf_5.x/6.x -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460830 - CVE-2026-33260 dnsdist: insufficient input validation of internal webserver [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460830 [ 2 ] Bug #2460831 - CVE-2026-33260 dnsdist: insufficient input validation of internal webserver[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460831 [ 3 ] Bug #2460832 - CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460832 [ 4 ] Bug #2460833 - CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460833 [ 5 ] Bug #2460834 - CVE-2026-33596 dnsdist: TCP backend stream ID overflow [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460834 [ 6 ] Bug #2460835 - CVE-2026-33596 dnsdist: TCP backend stream ID overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460835 [ 7 ] Bug #2460836 - CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460836 [ 8 ] Bug #2460837 - CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460837 [ 9 ] Bug #2460838 - CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460838 [ 10 ] Bug #2460839 - CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460839 [ 11 ] Bug #2460840 - CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460840 [ 12 ] Bug #2460841 - CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460841 [ 13 ] Bug #2460842 - CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460842 [ 14 ] Bug #2460843 - CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460843 [ 15 ] Bug #2460844 -CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460844 [ 16 ] Bug #2460845 - CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460845 [ 17 ] Bug #2460846 - CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460846 [ 18 ] Bug #2460847 - CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460847 [ 19 ] Bug #2460848 - CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460848 [ 20 ] Bug #2460849 - CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460849 [ 21 ] Bug #2460851 - CVE-2026-33593 dnsdist: denial of service via crafted DNSCrypt query [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460851 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-51cdd1292b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical security advisory on Fedora 44 for dnsdist addressing multiple denial of service vulnerabilities. Updates advised.. dnsdist security, Fedora update, denial of service, memory leak, critical security advisory. . Severity: Critical. LinuxSecurity.com Team
An update that solves 11 vulnerabilities can now be installed.. # dnsdist-2.0.5-1.1 on GA media Announcement ID: openSUSE-SU-2026:10632-1 Rating: moderate Cross-References: * CVE-2026-33254 * CVE-2026-33257 * CVE-2026-33260 * CVE-2026-33593 * CVE-2026-33594 * CVE-2026-33595 * CVE-2026-33596 * CVE-2026-33597 * CVE-2026-33598 * CVE-2026-33599 * CVE-2026-33602 CVSS scores: * CVE-2026-33257 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Tumbleweed An update that solves 11 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the dnsdist-2.0.5-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * dnsdist 2.0.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33254.html * https://www.suse.com/security/cve/CVE-2026-33257.html * https://www.suse.com/security/cve/CVE-2026-33260.html * https://www.suse.com/security/cve/CVE-2026-33593.html * https://www.suse.com/security/cve/CVE-2026-33594.html * https://www.suse.com/security/cve/CVE-2026-33595.html * https://www.suse.com/security/cve/CVE-2026-33596.html * https://www.suse.com/security/cve/CVE-2026-33597.html * https://www.suse.com/security/cve/CVE-2026-33598.html * https://www.suse.com/security/cve/CVE-2026-33599.html * https://www.suse.com/security/cve/CVE-2026-33602.html . Install openSUSE dnsdist 2.0.5-1.1 update fixing 11 moderate security issues for improved protection.. dnsdist update, openSUSE security, moderate severity vulnerabilities. . LinuxSecurity.com Team
Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or ACL bypass. For the stable distribution (trixie), these problems have been fixed in version 1.9.14-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6235-1
Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or ACL bypass. For the stable distribution (trixie), these problems have been fixed in version 4.9.14-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6233-1
Update to latest upstream. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-519446405a 2026-04-25 01:21:36.171663+00:00 -------------------------------------------------------------------------------- Name : dnsdist Product : Fedora 44 Version : 2.0.3 Release : 1.fc44 URL : https://dnsdist.org Summary : Highly DNS-, DoS- and abuse-aware loadbalancer Description : dnsdist is a highly DNS-, DoS- and abuse-aware loadbalancer. Its goal in life is to route traffic to the best server, delivering top performance to legitimate users while shunting or blocking abusive traffic. -------------------------------------------------------------------------------- Update Information: Update to latest upstream -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Sander Hoentjen - 2.0.3-1 - Update to new upstream - Fixes #2453419 (CVE-2026-27854) - Fixes #2453421 (CVE-2026-27853) - Fixes #2453426 (CVE-2026-24030) - Fixes #2453427 (CVE-2026-0397) - Fixes #2453429 (CVE-2026-24029) - Fixes #2453430 (CVE-2026-0396) - Fixes #2453431 (CVE-2026-24028) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419176 - dnsdist-2.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419176 [ 2 ] Bug #2453419 - CVE-2026-27854 dnsdist: DNSdist: Denial of Service due to use-after-free vulnerability in Lua [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453419 [ 3 ] Bug #2453421 - CVE-2026-27853 dnsdist: dnsdist: Denial of Service via crafted DNS responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453421 [ 4 ] Bug #2453426 - CVE-2026-24030 dnsdist: DNSdist: Denial of Service via excessive memory allocation from DNS over QUIC or HTTP/3 payloads [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453426 [ 5 ]Bug #2453427 - CVE-2026-0397 dnsdist: dnsdist and PowerDNS: Information Disclosure via Cross-Origin Resource Sharing (CORS) Misconfiguration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453427 [ 6 ] Bug #2453429 - CVE-2026-24029 dnsdist: dnsdist: Access Control List bypass allows unauthorized DNS over HTTPS queries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453429 [ 7 ] Bug #2453430 - CVE-2026-0396 dnsdist: dnsdist: HTML injection via crafted DNS queries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453430 [ 8 ] Bug #2453431 - CVE-2026-24028 dnsdist: dnsdist and PowerDNS: Denial of service or information disclosure via crafted DNS response packet [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453431 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-519446405a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.