openSUSE-SU-2026:21533-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21533-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21533-1
Upstream
Related
Published
2026-08-05T09:13:07Z
Modified
2026-08-06T18:23:57Z
Summary
Security update for dnsdist
Details

This update for dnsdist fixes the following issues:

Update to 1.9.15.

Changes for dnsdist:

Security issues fixed:

  • CVE-2026-40011: invalid output produced in the prometheus endpoint when a large number of crafted DNS queries are sent (bsc#1269204).
  • CVE-2026-40208: processing of DoH3 queries can be delayed via DoH3 GET queries with an invalid DATA frames (bsc#1269207).
  • CVE-2026-40209: outgoing TCP connections to backend can get stuck until a timeout occurs when specially crafted IXFR queries are sent (bsc#1269206).
  • CVE-2026-40210: out-of-bounds read when SetMacAddrAction is used can lead to uninitialized memory being sent over the network or a crash (bsc#1269205).
  • CVE-2026-40211: crafted DNS over HTTP/3 queries can trigger an exception that prevents memory from being freed and can lead to an OOM condition (bsc#1269203).
  • CVE-2026-42004: crafted EDNS OPT record will be ignored by filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted (bsc#1269202).
  • CVE-2026-42005: crafted web request can cause unlimited memory allocation in the internal web server and lead to a DoS (bsc#1269201).
References

Affected packages

openSUSE:Leap 16.0 / dnsdist

Package

Name
dnsdist
Purl
pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.15-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "dnsdist": "1.9.15-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21533-1.json"