{"id":"openSUSE-SU-2026:21533-1","summary":"Security update for dnsdist","details":"This update for dnsdist fixes the following issues:\n\nUpdate to 1.9.15.\n\nChanges for dnsdist:\n\n- https://www.dnsdist.org/changelog.html#change-1.9.15\n- https://www.dnsdist.org/changelog.html#change-1.9.14\n\nSecurity issues fixed:\n\n- CVE-2026-40011: invalid output produced in the prometheus endpoint when a large number of crafted DNS queries are sent\n  (bsc#1269204).\n- CVE-2026-40208: processing of DoH3 queries can be delayed via DoH3 GET queries with an invalid DATA frames\n  (bsc#1269207).\n- CVE-2026-40209: outgoing TCP connections to backend can get stuck until a timeout occurs when specially crafted IXFR\n  queries are sent (bsc#1269206).\n- CVE-2026-40210: out-of-bounds read when `SetMacAddrAction` is used can lead to uninitialized memory being sent over\n  the network or a crash (bsc#1269205).\n- CVE-2026-40211: crafted DNS over HTTP/3 queries can trigger an exception that prevents memory from being freed and can\n  lead to an OOM condition (bsc#1269203).\n- CVE-2026-42004: crafted EDNS OPT record will be ignored by filtering rules, but will be rewritten as a valid OPT\n  record when EDNS Client Subnet is inserted (bsc#1269202).\n- CVE-2026-42005: crafted web request can cause unlimited memory allocation in the internal web server and lead to a DoS\n  (bsc#1269201).\n","modified":"2026-08-06T18:23:57.734710349Z","published":"2026-08-05T09:13:07Z","related":["CVE-2026-40011","CVE-2026-40208","CVE-2026-40209","CVE-2026-40210","CVE-2026-40211","CVE-2026-42004","CVE-2026-42005"],"upstream":["CVE-2026-40011","CVE-2026-40208","CVE-2026-40209","CVE-2026-40210","CVE-2026-40211","CVE-2026-42004","CVE-2026-42005"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269201"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269203"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269204"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269206"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269207"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40208"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40210"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40211"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42004"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42005"}],"affected":[{"package":{"name":"dnsdist","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.15-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.9.15-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21533-1.json"}}],"schema_version":"1.8.0"}