Skip to content
Fedora 44 perl-Net-DNS Critical Remote Code Injection DoS 2026

Fedora 44 perl-Net-DNS Critical Remote Code Injection DoS 2026

Linuxsecurity •LinuxSecurity Advisories • September 10, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Net::DNS is a collection of Perl modules that act as a Domain Name System

(DNS) resolver. It allows the programmer to perform DNS queries that are

beyond the capabilities of gethostbyname and gethostbyaddr.

The programmer should be somewhat familiar with the format of a DNS packet and

its various sections. See RFC 1035 or DNS and BIND (Albitz & Liu) for details.

Update to Net-DNS 1.56 (from 1.53). Security fixes: - CVE-worthy: Remote code injection via EDNS EXTENDED ERROR (rt.cpan #179945) - Denial of Service via long DNS compression chains (rt.cpan #179946) - Resolver/UNIX.pm no longer relies on shell for uname (rt.cpan #176900) Bug fixes: - Fix TCP read loop treating 1-byte recv() of "0" (0x30) as EOF, which corrupted AXFRs (rt.cpan #177003) - Fix unhelpful TAINT error (rt.cpan #178183) - Fix unreachable-code warning under Apache/mod_perl (rt.cpan #179692/#176900) - Documentation fix for Net::DNS::RR::RRSIG::verify() (rt.cpan #180088). Other: - Resync with IANA DNS parameters and DNSSEC algorithm registries - New DNSKEY adt() accessor; DELEG parser backported to SVCB

* Mon Jul 20 2026 Jitka Plesnikova - 1.56-1 - 1.56 bump (rhbz#2501994) * Mon Jun 15 2026 Jitka Plesnikova - 1.55-1 - 1.55 bump (rhbz#2430556) - Update upstream GPG signing key (NLnet Labs releases signing key G2)

* Mon Jul 20 2026 Jitka Plesnikova - 1.56-1 - 1.56 bump (rhbz#2501994) * Mon Jun 15 2026 Jitka Plesnikova - 1.55-1 - 1.55 bump (rhbz#2430556) - Update upstream GPG signing key (NLnet Labs releases signing key G2)

[ 1 ] Bug #2509247 - CVE-2026-64193 perl-Net-DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling [fedora-all] [ 2 ] Bug #2509706 - CVE-2026-64194 perl-Net-DNS: Net::DNS: Denial of Service via crafted DNS compression pointers [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a0607111e6' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)

Platforms (2)

Tools (1)