Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
202

openSUSE ldns Important Remote Access Risk Advisory 2026-21093-1

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for ldns ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21093-1 Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for ldns fixes the following issue - CVE-2026-10846: when ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-958=1 Package List: - openSUSE Leap 16.0: ldns-1.8.4-160000.3.1 ldns-devel-1.8.4-160000.3.1 libldns3-1.8.4-160000.3.1 perl-DNS-LDNS-1.8.4-160000.3.1 python3-ldns-1.8.4-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-10846.html . Important openSUSE security update addresses ldns vulnerability CVE-2026-10846 with recommended installation methods.. openSUSE security, ldns update, important security patch, CVE-2026-10846. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important OpenSUSE
89

Fedora 43 ldns Important Update CVE-2026-10846 DoS Threat

Update to 1.9.2 for CVE-2026-10846. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b33ba1aa06 2026-06-27 00:54:50.049628+00:00 -------------------------------------------------------------------------------- Name : ldns Product : Fedora 43 Version : 1.9.2 Release : 1.fc43 URL : https://www.nlnetlabs.nl/ldns/ Summary : Low-level DNS(SEC) library with API Description : ldns is a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. -------------------------------------------------------------------------------- Update Information: Update to 1.9.2 for CVE-2026-10846 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 11 2026 Paul Wouters - 1.9.2-1 - Update to 1.9.2 for CVE-2026-10846 (re-release upstream) * Wed Jun 10 2026 Paul Wouters - 1.9.0-8 - Fix for CVE-2026-10846 * Wed Jun 3 2026 Python Maint - 1.9.0-3 - Rebuilt for Python 3.15 * Fri Jan 16 2026 Fedora Release Engineering - 1.9.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b33ba1aa06' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 43 ldns update addresses critical CVE-2026-10846. Ensure system security with the latest upgrade guidance.. Fedora Update, ldns Library, DNSSEC Security, CVE Patch, Important Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 Important Fedora
100

SUSE ldns Important Security Fix for CVE-2026-10846 2026-22167-1

An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:22167-1 Release Date: 2026-06-18T21:04:53Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: when ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-958=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-958=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DNS-LDNS-debuginfo-1.8.4-160000.3.1 * libldns3-debuginfo-1.8.4-160000.3.1 * ldns-debuginfo-1.8.4-160000.3.1 * ldns-debugsource-1.8.4-160000.3.1 * ldns-1.8.4-160000.3.1 * python3-ldns-1.8.4-160000.3.1 * perl-DNS-LDNS-1.8.4-160000.3.1 * libldns3-1.8.4-160000.3.1 * python3-ldns-debuginfo-1.8.4-160000.3.1 *ldns-devel-1.8.4-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.4-160000.3.1 * libldns3-debuginfo-1.8.4-160000.3.1 * ldns-debuginfo-1.8.4-160000.3.1 * ldns-debugsource-1.8.4-160000.3.1 * ldns-1.8.4-160000.3.1 * python3-ldns-1.8.4-160000.3.1 * perl-DNS-LDNS-1.8.4-160000.3.1 * libldns3-1.8.4-160000.3.1 * python3-ldns-debuginfo-1.8.4-160000.3.1 * ldns-devel-1.8.4-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html * https://bugzilla.suse.com/show_bug.cgi?id=1267670 . An important update for ldns resolves a security issue. Installation via SUSE recommended methods is advised.. SUSE security update, ldns patch, software vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2026 Important SuSE
100

SUSE ldns Important DoS Issue Fix Advisory 2026-2461-1 CVE-2026-10846

An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2461-1 Release Date: 2026-06-19T07:38:26Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypperin -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2461=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2461=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2461=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2461=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2461=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2461=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2461=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2461=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 *perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html *https://bugzilla.suse.com/show_bug.cgi?id=1267670 . Find essential information about the important security update for ldns on SUSE, addressing CVE-2026-10846 and its impact.. ldns update, security patch, SUSE Linux, security risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 19, 2026 Important SuSE
100

SUSE ldns Important DoS Vulnern SUSE-2026-2462-1 CVE-2026-10846

An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2462-1 Release Date: 2026-06-19T07:39:02Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2462=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2462=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2462=1 * SUSE Package Hub15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2462=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2462=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2462=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * python3-ldns-1.8.3-150600.3.3.1 * ldns-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * python3-ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * ldns-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html * https://bugzilla.suse.com/show_bug.cgi?id=1267670 . Important Security Update for ldns to address CVE-2026-10846, enhancing system protection against potential exploits.. SUSE Update Security ldns CVE-2026-10846. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 19, 2026 Important SuSE
172

Ubuntu 26.04 LTS ldns Important Spoofed DNS Response Risk USN-8449-1

ldns could be made to accept spoofed DNS responses.. ========================================================================== Ubuntu Security Notice USN-8449-1 June 18, 2026 ldns vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: ldns could be made to accept spoofed DNS responses. Software Description: - ldns: ldns library for DNS programming Details: Pablo Ruiz discovered that ldns did not properly validate DNS responses when used as a stub resolver over UDP. A remote attacker could possibly use this issue to inject arbitrary DNS responses. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS ldnsutils 1.8.4-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro libldns3t64 1.8.4-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS ldnsutils 1.8.3-2ubuntu0.1~esm1 Available with Ubuntu Pro libldns3t64 1.8.3-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS ldnsutils 1.7.1-2ubuntu4+esm2 Available with Ubuntu Pro libldns3 1.7.1-2ubuntu4+esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS ldnsutils 1.7.0-4.1ubuntu1+esm2 Available with Ubuntu Pro libldns2 1.7.0-4.1ubuntu1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS ldnsutils 1.7.0-3ubuntu4.1+esm1 Available with Ubuntu Pro libldns2 1.7.0-3ubuntu4.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS ldnsutils 1.6.17-8ubuntu0.1+esm2 Available with Ubuntu Pro libldns1 1.6.17-8ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8449-1 CVE-2026-10846 . A crucial update on ldns vulnerabilities affecting multiple Ubuntu LTS versions. Important patch instructions included.. DNS Spoofing, ldns Security, Ubuntu Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Important Ubuntu
89

Fedora 44 ldns Critical CVE-2026-10846 Security Patch Released

Update to 1.9.2 for CVE-2026-10846. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1c6479b257 2026-06-17 08:41:51.002489+00:00 -------------------------------------------------------------------------------- Name : ldns Product : Fedora 44 Version : 1.9.2 Release : 1.fc44 URL : https://www.nlnetlabs.nl/ldns/ Summary : Low-level DNS(SEC) library with API Description : ldns is a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. -------------------------------------------------------------------------------- Update Information: Update to 1.9.2 for CVE-2026-10846 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 11 2026 Paul Wouters - 1.9.2-1 - Update to 1.9.2 for CVE-2026-10846 (re-release upstream) * Wed Jun 10 2026 Paul Wouters - 1.9.0-8 - Fix for CVE-2026-10846 * Wed Jun 3 2026 Python Maint - 1.9.0-3 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1c6479b257' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical update for Fedora 44 addresses CVE-2026-10846 in ldns, enhancing security against potential threats.. Fedora update, ldns library, security patch, CVE-2026-10846, DNSSEC library. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2026 Important Fedora
202

openSUSE Tumbleweed ldns Moderate Security Update CVE-2026-10846

An update that solves one vulnerability can now be installed.. # ldns-1.9.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10998-1 Rating: moderate Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the ldns-1.9.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ldns 1.9.2-1.1 * ldns-devel 1.9.2-1.1 * libldns3 1.9.2-1.1 * perl-DNS-LDNS 1.9.2-1.1 * python3-ldns 1.9.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html . An update for openSUSE Tumbleweed addresses a moderate severity issue in ldns. Install to mitigate risks.. openSUSE updates, ldns security, moderate severity, installation guide, Tumbleweed vulnerabilities. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 moderate OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200