MGASA-2026-0448

Source
https://advisories.mageia.org/MGASA-2026-0448.html
Import Source
https://advisories.mageia.org/MGASA-2026-0448.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0448
Upstream
CVE (3)
  • CVE-2026-64193
  • CVE-2026-64194
  • CVE-2026-81928
Published
2026-09-24T16:06:15Z
Modified
2026-09-24T16:15:03Z
Summary
Updated perl-Net-DNS packages fix security vulnerabilities
Details

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. (CVE-2026-64193) Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. (CVE-2026-64194) Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. (CVE-2026-81928)

References
Credits

Affected packages

Mageia:10 / perl-Net-DNS

Package

Name
perl-Net-DNS
Purl
pkg:rpm/mageia/perl-Net-DNS?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.570.0-1.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0448.json"

Mageia:9 / perl-Net-DNS

Package

Name
perl-Net-DNS
Purl
pkg:rpm/mageia/perl-Net-DNS?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.360.0-1.1.mga9

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0448.json"