{"id":"SUSE-SU-2026:23123-1","summary":"Security update for dnsdist","details":"This update for dnsdist fixes the following issues:\n\nUpdate to 1.9.15.\n\nChanges for dnsdist:\n\n- https://www.dnsdist.org/changelog.html#change-1.9.15\n- https://www.dnsdist.org/changelog.html#change-1.9.14\n\nSecurity issues fixed:\n\n- CVE-2026-40011: invalid output produced in the prometheus endpoint when a large number of crafted DNS queries are sent\n  (bsc#1269204).\n- CVE-2026-40208: processing of DoH3 queries can be delayed via DoH3 GET queries with an invalid DATA frames\n  (bsc#1269207).\n- CVE-2026-40209: outgoing TCP connections to backend can get stuck until a timeout occurs when specially crafted IXFR\n  queries are sent (bsc#1269206).\n- CVE-2026-40210: out-of-bounds read when `SetMacAddrAction` is used can lead to uninitialized memory being sent over\n  the network or a crash (bsc#1269205).\n- CVE-2026-40211: crafted DNS over HTTP/3 queries can trigger an exception that prevents memory from being freed and can\n  lead to an OOM condition (bsc#1269203).\n- CVE-2026-42004: crafted EDNS OPT record will be ignored by filtering rules, but will be rewritten as a valid OPT\n  record when EDNS Client Subnet is inserted (bsc#1269202).\n- CVE-2026-42005: crafted web request can cause unlimited memory allocation in the internal web server and lead to a DoS\n  (bsc#1269201).\n","modified":"2026-08-14T18:23:39.882232948Z","published":"2026-08-05T09:14:01Z","related":["CVE-2026-40011","CVE-2026-40208","CVE-2026-40209","CVE-2026-40210","CVE-2026-40211","CVE-2026-42004","CVE-2026-42005"],"upstream":["CVE-2026-40011","CVE-2026-40208","CVE-2026-40209","CVE-2026-40210","CVE-2026-40211","CVE-2026-42004","CVE-2026-42005"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623123-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269201"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269203"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269204"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269206"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269207"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40208"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40210"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40211"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42004"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42005"}],"affected":[{"package":{"name":"dnsdist","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.15-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.9.15-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23123-1.json"}},{"package":{"name":"dnsdist","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/dnsdist&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.15-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.9.15-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23123-1.json"}}],"schema_version":"1.9.0"}