Linuxsecurity Fedora SpoofDPI Vulnerability Fixes Address Denial of Service Risk
Article Content
- •Fedora updates SpoofDPI to fix CVE-2026-27145 affecting DNS SAN processing.
- •Denial of service vulnerability could lead to significant service disruptions.
- •Users are urged to upgrade using the 'dnf' update program to mitigate risks.
Fedora has released updates for the SpoofDPI tool to address a moderate configuration issue and a major denial of service vulnerability. The vulnerabilities are linked to CVE-2026-27145, which affects the processing of DNS SAN entries in the golang crypto/x509 package. The updates were published on July 14, 2026, and include version 1.5.3 of SpoofDPI. Users are advised to upgrade to mitigate potential exploitation risks. The vulnerabilities could allow for excessive processing, leading to service disruptions. The updates can be installed via the 'dnf' update program. Fedora 43 and Fedora 44 users are impacted by these vulnerabilities. The issues have been resolved in the latest updates, with specific advisories issued for both versions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-27145 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Denial of Service Vulnerability in grpcurl Affects Fedora Systems A denial of service vulnerability (CVE-2026-27145) has been identified in grpcurl, a command-line tool for interacting with gRPC servers, affecting Fedora systems. The vulnerability allows for excessive processing of DNS SAN entries, potentially leading to service disruption. Fedora versions 1.9.3 and earlier are…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…