Linuxsecurity Critical Access Control and DoS Vulnerabilities in CoreDNS Addressed
Article Content
- •CoreDNS updates address critical vulnerabilities CVE-2026-26017 and CVE-2026-26018.
- •CVE-2025-68156 fixed uncontrolled recursion leading to denial of service.
- •Patches are available for openSUSE and Fedora users; immediate application is recommended.
Recent updates for CoreDNS have addressed significant vulnerabilities affecting DNS services. The updates include fixes for CVE-2026-26017, which resolves an access control bypass due to a flaw in the execution order of plugins, and CVE-2026-26018, which mitigates a denial of service vulnerability linked to predictable pseudo-random number generation. Additionally, CVE-2025-68156 has been patched to prevent uncontrolled recursion in expression evaluation, which can also lead to denial of service. These vulnerabilities impact users of openSUSE and Fedora systems utilizing CoreDNS versions prior to the updates. The patches are available through standard installation methods like YaST and zypper. Users are advised to apply the updates promptly to secure their systems against potential exploitation. The vulnerabilities were disclosed on March 6, 2026, and the updates were released on March 11, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-61726 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…