{"id":"openSUSE-SU-2026:21015-1","summary":"Security update for dnsdist","details":"This update for dnsdist fixes the following issues\n\n- CVE-2026-0396: crafted DNS queries can allow to inject HTML content (bsc#1261236).\n- CVE-2026-0397: CORS misconfiguration can lead to information disclosure (bsc#1261237).\n- CVE-2026-24028: crafted DNS response packet can lead to an out-of-bounds read (bsc#1261238).\n- CVE-2026-24029: HTTPS ACL bypass can allow clients to send DoH queries (bsc#1261239).\n- CVE-2026-24030: allocating too much memory while processing DNS can result in a denial of service (bsc#1261240).\n- CVE-2026-27853: crafted DNS responses can lead to an out-of-bounds write (bsc#1261241).\n- CVE-2026-27854: crafted DNS queries can be used to trigger a use-after-free (bsc#1261243).\n- CVE-2026-33254: Resource exhaustion via DoQ/DoH3 connections (bsc#1262538).\n- CVE-2026-33257: Insufficient input validation of internal webserver (bsc#1262536).\n- CVE-2026-33260: Insufficient input validation of internal webserver (bsc#1262537).\n- CVE-2026-33593: Denial of service via crafted DNSCrypt query (bsc#1262546).\n- CVE-2026-33594: Outgoing DoH excessive memory allocation (bsc#1262545).\n- CVE-2026-33595: DoQ/DoH3 excessive memory allocation (bsc#1262544).\n- CVE-2026-33596: TCP backend stream ID overflow (bsc#1262543).\n- CVE-2026-33597: PRSD detection denial of service (bsc#1262542).\n- CVE-2026-33598: Out-of-bounds read in cache inspection via Lua (bsc#1262541).\n- CVE-2026-33599: Out-of-bounds read in service discovery (bsc#1262540).\n- CVE-2026-33602: Off-by-one access when processing crafted UDP responses (bsc#1262539).\n\nChanges for dnsdist:\n\n- Updated to 1.9.13\n","modified":"2026-06-30T18:24:41.952837616Z","published":"2026-06-22T14:30:36Z","related":["CVE-2026-0396","CVE-2026-0397","CVE-2026-24028","CVE-2026-24029","CVE-2026-24030","CVE-2026-27853","CVE-2026-27854","CVE-2026-33254","CVE-2026-33257","CVE-2026-33260","CVE-2026-33593","CVE-2026-33594","CVE-2026-33595","CVE-2026-33596","CVE-2026-33597","CVE-2026-33598","CVE-2026-33599","CVE-2026-33602"],"upstream":["CVE-2026-0396","CVE-2026-0397","CVE-2026-24028","CVE-2026-24029","CVE-2026-24030","CVE-2026-27853","CVE-2026-27854","CVE-2026-33254","CVE-2026-33257","CVE-2026-33260","CVE-2026-33593","CVE-2026-33594","CVE-2026-33595","CVE-2026-33596","CVE-2026-33597","CVE-2026-33598","CVE-2026-33599","CVE-2026-33602"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261236"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261237"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261239"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261240"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261241"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261243"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262536"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262537"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262538"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262539"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262540"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262541"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262542"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262543"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262544"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262545"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0396"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0397"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27853"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33257"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33260"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33593"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33594"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33596"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33602"}],"affected":[{"package":{"name":"dnsdist","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.13-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dnsdist":"1.9.13-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21015-1.json"}}],"schema_version":"1.7.5"}