openSUSE-SU-2026:21859-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21859-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21859-1
Upstream
CVE (3)
  • CVE-2026-64193
  • CVE-2026-64194
  • CVE-2026-81928
Related
Published
2026-09-15T13:20:42Z
Modified
2026-09-17T18:23:16Z
Summary
Security update for perl-Net-DNS
Details

This update for perl-Net-DNS fixes the following issues:

Changes in perl-Net-DNS:

Updated to 1.570.0 (1.57):

See /usr/share/doc/packages/perl-Net-DNS/Changes .

  • Resync with IANA DNS parameters registry.
    
  • EDNS: Add support for MQTYPE-QUERY option.
    
  • Unbounded recursion when re-encoding message with misplaced TSIG CVE-2026-81928 bsc#1278084
    
  • UNIX resolver can fail in taint mode
    
  • Documentation issue for Net::DNS::RR::RRSIG::verify()
    
  • Denial of Service via long DNS compression chains CVE-2026-64194 bsc#1272214
    
  • Remote code injection via EDNS EXTENDED ERROR CVE-2026-64193 bsc#1272212
    
  • UNIX.pm: Unreachable code warning using Apache/mod_perl
    
References

Affected packages

openSUSE:Leap 16.0 / perl-Net-DNS

Package

Name
perl-Net-DNS
Purl
pkg:rpm/opensuse/perl-Net-DNS&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.570.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "perl-Net-DNS":  "1.570.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21859-1.json"