{"id":"openSUSE-SU-2026:21859-1","summary":"Security update for perl-Net-DNS","details":"This update for perl-Net-DNS fixes the following issues:\n\nChanges in perl-Net-DNS:\n\nUpdated to 1.570.0 (1.57):\n\nSee /usr/share/doc/packages/perl-Net-DNS/Changes .\n\n  -     Resync with IANA DNS parameters registry.\n  -     EDNS: Add support for MQTYPE-QUERY option.\n  -     Unbounded recursion when re-encoding message with misplaced TSIG CVE-2026-81928 bsc#1278084\n  -     UNIX resolver can fail in taint mode\n\n  -     Documentation issue for Net::DNS::RR::RRSIG::verify()\n  -     Denial of Service via long DNS compression chains CVE-2026-64194 bsc#1272214\n  -     Remote code injection via EDNS EXTENDED ERROR CVE-2026-64193 bsc#1272212\n  -     UNIX.pm: Unreachable code warning using Apache/mod_perl\n","modified":"2026-09-17T18:23:16.206853539Z","published":"2026-09-15T13:20:42Z","related":["CVE-2026-64193","CVE-2026-64194","CVE-2026-81928"],"upstream":["CVE-2026-64193","CVE-2026-64194","CVE-2026-81928"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272212"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272214"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278084"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64193"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64194"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81928"}],"affected":[{"package":{"name":"perl-Net-DNS","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/perl-Net-DNS&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.570.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"perl-Net-DNS":"1.570.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21859-1.json"}}],"schema_version":"1.9.0"}