Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20461-1

Опубликовано: 02 апр. 2026
Источник: suse-cvrf

Описание

Security update for dnsdist

This update for dnsdist fixes the following issues:

Update to dnsdist 1.9.11:

  • CVE-2025-8671: add mitigations for the HTTP/2 MadeYouReset attack (bsc#1253852).
  • CVE-2025-30187: denial of service via crafted DoH exchange (bsc#1250054).

Список пакетов

openSUSE Leap 16.0
dnsdist-1.9.11-160000.1.1

Описание

In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.


Затронутые продукты
openSUSE Leap 16.0:dnsdist-1.9.11-160000.1.1

Ссылки

Описание

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them-using malformed frames or flow control errors-an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.


Затронутые продукты
openSUSE Leap 16.0:dnsdist-1.9.11-160000.1.1

Ссылки