openSUSE-SU-2026:20619-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20619-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20619-1
Upstream
Related
Published
2026-04-23T16:09:35Z
Modified
2026-04-25T07:46:09.567616Z
Summary
Security update for coredns
Details

This update for coredns fixes the following issues:

Changes in coredns:

  • Update to version 1.14.2:

    • plugin/reload: Allow disabling jitter with 0s
    • bump deps
    • plugin/forward: fix parsing error when handling TLS+IPv6 address
    • plugin/loop: use crypto/rand for query name generation
    • plugin: reorder rewrite before acl to prevent bypass
    • fix(rewrite): fix cname target rewrite for CNAME chains
    • fix(kubernetes): panic on empty ListenHosts
    • chore: bump minimum Go version to 1.25
    • feat(proxyproto): add proxy protocol support
    • refactor(cache): modernize with generics
    • Add metadata for response Type and Class to Log
    • docs: clarify kubernetes auth docs
    • fix: return SOA and NS records when queried for a record CNAMEd to origin
  • fixes bsc#1259320 CVE-2026-26017

  • fixes bsc#1259319 CVE-2026-26018

  • address more unstable unstable tests under aarch64 and s390x

  • Update to version 1.14.1:

    • This release primarily addresses security vulnerabilities affecting Go versions prior to Go 1.25.6 and Go 1.24.12 (CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2025-61731, CVE-2025-68119). It also includes performance improvements to the proxy plugin via multiplexed connections, along with various documentation updates.
References

Affected packages

openSUSE:Leap 16.0 / coredns

Package

Name
coredns
Purl
pkg:rpm/opensuse/coredns&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.14.2-bp160.1.1

Ecosystem specific

{
    "binaries": [
        {
            "coredns": "1.14.2-bp160.1.1",
            "coredns-extras": "1.14.2-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20619-1.json"