{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20619-1","published":"2026-04-23T16:09:35Z","modified":"2026-04-25T07:46:09.567616Z","related":["CVE-2025-61726","CVE-2025-61728","CVE-2025-61731","CVE-2025-68119","CVE-2025-68121","CVE-2026-26017","CVE-2026-26018"],"upstream":["CVE-2025-61726","CVE-2025-61728","CVE-2025-61731","CVE-2025-68119","CVE-2025-68121","CVE-2026-26017","CVE-2026-26018"],"summary":"Security update for coredns","details":"This update for coredns fixes the following issues:\n\nChanges in coredns:\n\n- Update to version 1.14.2:\n  * plugin/reload: Allow disabling jitter with 0s\n  * bump deps\n  * plugin/forward: fix parsing error when handling TLS+IPv6 address\n  * plugin/loop: use crypto/rand for query name generation\n  * plugin: reorder rewrite before acl to prevent bypass\n  * fix(rewrite): fix cname target rewrite for CNAME chains\n  * fix(kubernetes): panic on empty ListenHosts\n  * chore: bump minimum Go version to 1.25\n  * feat(proxyproto): add proxy protocol support\n  * refactor(cache): modernize with generics\n  * Add metadata for response Type and Class to Log\n  * docs: clarify kubernetes auth docs\n  * fix: return SOA and NS records when queried for a record CNAMEd to origin\n\n- fixes bsc#1259320 CVE-2026-26017\n- fixes bsc#1259319 CVE-2026-26018\n\n- address more unstable unstable tests under aarch64 and s390x\n\n- Update to version 1.14.1:\n  * This release primarily addresses security vulnerabilities affecting Go\n    versions prior to Go 1.25.6 and Go 1.24.12\n    (CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2025-61731,\n     CVE-2025-68119).\n     It also includes performance improvements to the proxy plugin via\n     multiplexed connections, along with various documentation updates.\n","affected":[{"package":{"name":"coredns","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/coredns&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.2-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"coredns":"1.14.2-bp160.1.1","coredns-extras":"1.14.2-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20619-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259320"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61728"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61731"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68121"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26018"}]}