{"schema_version":"1.7.3","id":"openSUSE-SU-2025:0131-1","published":"2025-04-19T22:01:42Z","modified":"2026-02-04T03:35:24.332585Z","related":["CVE-2024-51744"],"upstream":["CVE-2024-51744"],"summary":"Security update for coredns","details":"This update for coredns fixes the following issues:\n\n- Update to version 1.12.1:\n  * core: Increase CNAME lookup limit from 7 to 10 (#7153)\n  * plugin/kubernetes: Fix handling of pods having DeletionTimestamp set\n  * plugin/kubernetes: Revert 'only create PTR records for endpoints with \n    hostname defined'\n  * plugin/forward: added option failfast_all_unhealthy_upstreams to return \n    servfail if all upstreams are down\n  * bump dependencies, fixing boo#1239294 and boo#1239728\n\n- Update to version 1.12.0:\n  * New multisocket plugin - allows CoreDNS to listen on multiple sockets\n  * bump deps\n\n- Update to version 1.11.4:\n  * forward plugin: new option next, to try alternate upstreams when receiving\n    specified response codes upstreams on (functions like the external plugin \n    alternate)\n  * dnssec plugin: new option to load keys from AWS Secrets Manager\n  * rewrite plugin: new option to revert EDNS0 option rewrites in responses\n\n- Update to version 1.11.3+git129.387f34d:\n  * fix CVE-2024-51744 (bsc#1232991)\n    build(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 (#6955)\n  * core: set cache-control max-age as integer, not float (#6764)\n  * Issue-6671: Fixed the order of plugins. (#6729)\n  * `root`: explicit mark `dnssec` support (#6753)\n  * feat: dnssec load keys from AWS Secrets Manager (#6618)\n  * fuzzing: fix broken oss-fuzz build (#6880)\n  * Replace k8s.io/utils/strings/slices by Go stdlib slices (#6863)\n  * Update .go-version to 1.23.2 (#6920)\n  * plugin/rewrite: Add 'revert' parameter for EDNS0 options (#6893)\n  * Added OpenSSF Scorecard Badge (#6738)\n  * fix(cwd): Restored backwards compatibility of Current Workdir (#6731)\n  * fix: plugin/auto: call OnShutdown() for each zone at its own OnShutdown() (#6705)\n  * feature: log queue and buffer memory size configuration (#6591)\n  * plugin/bind: add zone for link-local IPv6 instead of skipping (#6547)\n  * only create PTR records for endpoints with hostname defined (#6898)\n  * fix: reverter should execute the reversion in reversed order (#6872)\n  * plugin/etcd: fix etcd connection leakage when reload (#6646)\n  * kubernetes: Add useragent (#6484)\n  * Update build (#6836)\n  * Update grpc library use (#6826)\n  * Bump go version from 1.21.11 to 1.21.12 (#6800)\n  * Upgrade antonmedv/expr to expr-lang/expr (#6814)\n  * hosts: add hostsfile as label for coredns_hosts_entries (#6801)\n  * fix TestCorefile1 panic for nil handling (#6802)\n","affected":[{"package":{"name":"coredns","ecosystem":"SUSE:Package Hub 15 SP6","purl":"pkg:rpm/suse/coredns&distro=SUSE%20Package%20Hub%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.1-bp156.4.6.5"}]}],"ecosystem_specific":{"binaries":[{"coredns":"1.12.1-bp156.4.6.5","coredns-extras":"1.12.1-bp156.4.6.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:0131-1.json"}},{"package":{"name":"coredns","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/coredns&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.1-bp156.4.6.5"}]}],"ecosystem_specific":{"binaries":[{"coredns":"1.12.1-bp156.4.6.5","coredns-extras":"1.12.1-bp156.4.6.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:0131-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EUVFYQAJREBRWHGVJH4PINWMTHG2NH7G/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239294"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239728"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-51744"}]}