Critical Remote Code Execution Vulnerability in Fedora's perl-Net-DNS

Critical Remote Code Execution Vulnerability in Fedora's perl-Net-DNS

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Fedora has released an advisory for a critical vulnerability in the perl-Net-DNS module affecting versions 1.53 to 1.56. The vulnerabilities, identified as CVE-2026-64193 and CVE-2026-64194, allow for remote code execution and denial of service through crafted DNS queries. The flaws stem from improper handling of EDNS EXTENDED ERROR and long DNS compression chains. Users are advised to upgrade to version 1.56 to mitigate these risks. The vulnerabilities were published on July 20, 2026, and are confirmed to affect all Fedora systems running the affected versions. The advisory emphasizes the urgency of applying the patch due to the potential for exploitation. The update can be installed using the 'dnf' package manager, and detailed instructions are provided in the advisory.

Key Points: • Critical vulnerabilities in perl-Net-DNS allow remote code execution and DoS. • Affected versions include 1.53 to 1.56; users must upgrade to 1.56. • CVE-2026-64193 and CVE-2026-64194 were published on July 20, 2026.

Ask AI about this cluster

Timeline

2026-07-20
CVE-2026-64193 published
CVE-2026-64193 details arbitrary code execution via EDNS EXTENDED ERROR handling in perl-Net-DNS.
Linuxsecurity
2026-07-20
CVE-2026-64194 published
CVE-2026-64194 describes denial of service via crafted DNS compression pointers in perl-Net-DNS.
Linuxsecurity
2026-09-10
Fedora advisory released
Fedora issued an advisory urging users to update perl-Net-DNS to version 1.56 to address critical vulnerabilities.
Linuxsecurity