Updated perl-Net-DNS packages fix security vulnerabilities
Publication date: 24 Sep 2026Modification date: 24 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64193 , CVE-2026-64194 , CVE-2026-81928
Description
Net::DNS versions through 1.55 for Perl allow remote execution injection
via EDNS EXTENDED ERROR. (CVE-2026-64193)
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep
DNS compression pointer chains. (CVE-2026-64194)
Net::DNS versions before 1.57 for Perl allow memory exhaustion via
unbounded recursion in sig_data when re-encoding a message with a
misplaced TSIG record. (CVE-2026-81928)
References
- https://bugs.mageia.org/show_bug.cgi?id=35968
- https://www.openwall.com/lists/oss-security/2026/07/20/12
- https://www.openwall.com/lists/oss-security/2026/07/20/13
- https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56
- https://rt.cpan.org/Ticket/Display.html?id=179945
- https://rt.cpan.org/Ticket/Display.html?id=179946
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes
- https://lists.debian.org/debian-security-announce/2026/msg00370.html
- https://www.openwall.com/lists/oss-security/2026/09/02/1
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.56/source/lib/Net/DNS/RR/TSIG.pm#L245-262
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.56/source/lib/Net/DNS/RR/TSIG.pm#L62-73
- https://datatracker.ietf.org/doc/html/rfc8945#section-5.2
- https://rt.cpan.org/Ticket/Display.html?id=181125
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.57/changes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5TS4YPB3LGX5Q5VWSYLSIQZWXJU4UMZN/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GGGP7EQRAUOGLVT6K5VJ7U3KCA7YMNZZ/
- https://www.cve.org/CVERecord?id=CVE-2026-64193
- https://www.cve.org/CVERecord?id=CVE-2026-64194
- https://www.cve.org/CVERecord?id=CVE-2026-81928
SRPMS
10/core
- perl-Net-DNS-1.570.0-1.mga10
9/core
- perl-Net-DNS-1.360.0-1.1.mga9