Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for ldns ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21093-1 Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for ldns fixes the following issue - CVE-2026-10846: when ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-958=1 Package List: - openSUSE Leap 16.0: ldns-1.8.4-160000.3.1 ldns-devel-1.8.4-160000.3.1 libldns3-1.8.4-160000.3.1 perl-DNS-LDNS-1.8.4-160000.3.1 python3-ldns-1.8.4-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-10846.html . Important openSUSE security update addresses ldns vulnerability CVE-2026-10846 with recommended installation methods.. openSUSE security, ldns update, important security patch, CVE-2026-10846. . Severity: Important. LinuxSecurity.com Team
Update to 1.9.2 for CVE-2026-10846. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b33ba1aa06 2026-06-27 00:54:50.049628+00:00 -------------------------------------------------------------------------------- Name : ldns Product : Fedora 43 Version : 1.9.2 Release : 1.fc43 URL : https://www.nlnetlabs.nl/ldns/ Summary : Low-level DNS(SEC) library with API Description : ldns is a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. -------------------------------------------------------------------------------- Update Information: Update to 1.9.2 for CVE-2026-10846 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 11 2026 Paul Wouters - 1.9.2-1 - Update to 1.9.2 for CVE-2026-10846 (re-release upstream) * Wed Jun 10 2026 Paul Wouters - 1.9.0-8 - Fix for CVE-2026-10846 * Wed Jun 3 2026 Python Maint - 1.9.0-3 - Rebuilt for Python 3.15 * Fri Jan 16 2026 Fedora Release Engineering - 1.9.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b33ba1aa06' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:22167-1 Release Date: 2026-06-18T21:04:53Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: when ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-958=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-958=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DNS-LDNS-debuginfo-1.8.4-160000.3.1 * libldns3-debuginfo-1.8.4-160000.3.1 * ldns-debuginfo-1.8.4-160000.3.1 * ldns-debugsource-1.8.4-160000.3.1 * ldns-1.8.4-160000.3.1 * python3-ldns-1.8.4-160000.3.1 * perl-DNS-LDNS-1.8.4-160000.3.1 * libldns3-1.8.4-160000.3.1 * python3-ldns-debuginfo-1.8.4-160000.3.1 *ldns-devel-1.8.4-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.4-160000.3.1 * libldns3-debuginfo-1.8.4-160000.3.1 * ldns-debuginfo-1.8.4-160000.3.1 * ldns-debugsource-1.8.4-160000.3.1 * ldns-1.8.4-160000.3.1 * python3-ldns-1.8.4-160000.3.1 * perl-DNS-LDNS-1.8.4-160000.3.1 * libldns3-1.8.4-160000.3.1 * python3-ldns-debuginfo-1.8.4-160000.3.1 * ldns-devel-1.8.4-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html * https://bugzilla.suse.com/show_bug.cgi?id=1267670 . An important update for ldns resolves a security issue. Installation via SUSE recommended methods is advised.. SUSE security update, ldns patch, software vulnerability fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2461-1 Release Date: 2026-06-19T07:38:26Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypperin -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2461=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2461=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2461=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2461=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2461=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2461=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2461=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2461=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 *perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DNS-LDNS-1.7.0-150000.4.11.1 * ldns-debuginfo-1.7.0-150000.4.11.1 * libldns2-1.7.0-150000.4.11.1 * ldns-debugsource-1.7.0-150000.4.11.1 * ldns-devel-1.7.0-150000.4.11.1 * perl-DNS-LDNS-debuginfo-1.7.0-150000.4.11.1 * libldns2-debuginfo-1.7.0-150000.4.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html *https://bugzilla.suse.com/show_bug.cgi?id=1267670 . Find essential information about the important security update for ldns on SUSE, addressing CVE-2026-10846 and its impact.. ldns update, security patch, SUSE Linux, security risk. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for ldns Announcement ID: SUSE-SU-2026:2462-1 Release Date: 2026-06-19T07:39:02Z Rating: important References: * bsc#1267670 Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ldns fixes the following issue * CVE-2026-10846: When ldns is used by applications for (stub) resolving, it does not sufficiently verify that received responses belong to a sent query (bsc#1267670). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2462=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2462=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2462=1 * SUSE Package Hub15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2462=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2462=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2462=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * python3-ldns-1.8.3-150600.3.3.1 * ldns-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * python3-ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * ldns-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DNS-LDNS-debuginfo-1.8.3-150600.3.3.1 * perl-DNS-LDNS-1.8.3-150600.3.3.1 * libldns3-1.8.3-150600.3.3.1 * ldns-debuginfo-1.8.3-150600.3.3.1 * ldns-debugsource-1.8.3-150600.3.3.1 * ldns-devel-1.8.3-150600.3.3.1 * libldns3-debuginfo-1.8.3-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html * https://bugzilla.suse.com/show_bug.cgi?id=1267670 . Important Security Update for ldns to address CVE-2026-10846, enhancing system protection against potential exploits.. SUSE Update Security ldns CVE-2026-10846. . Severity: Important. LinuxSecurity.com Team
ldns could be made to accept spoofed DNS responses.. ========================================================================== Ubuntu Security Notice USN-8449-1 June 18, 2026 ldns vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: ldns could be made to accept spoofed DNS responses. Software Description: - ldns: ldns library for DNS programming Details: Pablo Ruiz discovered that ldns did not properly validate DNS responses when used as a stub resolver over UDP. A remote attacker could possibly use this issue to inject arbitrary DNS responses. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS ldnsutils 1.8.4-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro libldns3t64 1.8.4-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS ldnsutils 1.8.3-2ubuntu0.1~esm1 Available with Ubuntu Pro libldns3t64 1.8.3-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS ldnsutils 1.7.1-2ubuntu4+esm2 Available with Ubuntu Pro libldns3 1.7.1-2ubuntu4+esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS ldnsutils 1.7.0-4.1ubuntu1+esm2 Available with Ubuntu Pro libldns2 1.7.0-4.1ubuntu1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS ldnsutils 1.7.0-3ubuntu4.1+esm1 Available with Ubuntu Pro libldns2 1.7.0-3ubuntu4.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS ldnsutils 1.6.17-8ubuntu0.1+esm2 Available with Ubuntu Pro libldns1 1.6.17-8ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8449-1 CVE-2026-10846 . A crucial update on ldns vulnerabilities affecting multiple Ubuntu LTS versions. Important patch instructions included.. DNS Spoofing, ldns Security, Ubuntu Vulnerability. . Severity: Important. LinuxSecurity.com Team
Update to 1.9.2 for CVE-2026-10846. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1c6479b257 2026-06-17 08:41:51.002489+00:00 -------------------------------------------------------------------------------- Name : ldns Product : Fedora 44 Version : 1.9.2 Release : 1.fc44 URL : https://www.nlnetlabs.nl/ldns/ Summary : Low-level DNS(SEC) library with API Description : ldns is a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. -------------------------------------------------------------------------------- Update Information: Update to 1.9.2 for CVE-2026-10846 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 11 2026 Paul Wouters - 1.9.2-1 - Update to 1.9.2 for CVE-2026-10846 (re-release upstream) * Wed Jun 10 2026 Paul Wouters - 1.9.0-8 - Fix for CVE-2026-10846 * Wed Jun 3 2026 Python Maint - 1.9.0-3 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1c6479b257' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # ldns-1.9.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10998-1 Rating: moderate Cross-References: * CVE-2026-10846 CVSS scores: * CVE-2026-10846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-10846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the ldns-1.9.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ldns 1.9.2-1.1 * ldns-devel 1.9.2-1.1 * libldns3 1.9.2-1.1 * perl-DNS-LDNS 1.9.2-1.1 * python3-ldns 1.9.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10846.html . An update for openSUSE Tumbleweed addresses a moderate severity issue in ldns. Install to mitigate risks.. openSUSE updates, ldns security, moderate severity, installation guide, Tumbleweed vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.