Advisories ยป MGASA-2026-0448

Updated perl-Net-DNS packages fix security vulnerabilities

Publication date: 24 Sep 2026
Modification date: 24 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64193 , CVE-2026-64194 , CVE-2026-81928

Description

Net::DNS versions through 1.55 for Perl allow remote execution injection
via EDNS EXTENDED ERROR. (CVE-2026-64193)
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep
DNS compression pointer chains. (CVE-2026-64194)
Net::DNS versions before 1.57 for Perl allow memory exhaustion via
unbounded recursion in sig_data when re-encoding a message with a
misplaced TSIG record. (CVE-2026-81928)
                

References

SRPMS

10/core

9/core