RHSA-2026:68786HighCVSS 7.5

Red Hat Security Advisory: perl-Net-DNS security update

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-81928 — perl-Net-DNS: Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records

🎯 Affected products5

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • perl-Net-DNS-0:1.29-6.el9_8.1.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • perl-Net-DNS-0:1.29-6.el9_8.1.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • perl-Net-DNS-Nameserver-0:1.29-6.el9_8.1.noarch as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to DNS services utilizing `perl-Net-DNS` to trusted clients or internal networks only, thereby limiting exposure. If the DNS service is not required to act as a forwarder or proxy, disable this functionality to prevent the vulnerable code path from being exercised.

🔗 References (4)