Fedora SpoofDPI Vulnerability Fixes Address Denial of Service Risk

Fedora SpoofDPI Vulnerability Fixes Address Denial of Service Risk

First seen 19 Jul 2026, 08:42 UTC Linuxsecurity 78% similarity 57.8

Article Content

Browse articles
ThreatCluster

Fedora has released updates for the SpoofDPI tool to address a moderate configuration issue and a major denial of service vulnerability. The vulnerabilities are linked to CVE-2026-27145, which affects the processing of DNS SAN entries in the golang crypto/x509 package. The updates were published on July 14, 2026, and include version 1.5.3 of SpoofDPI. Users are advised to upgrade to mitigate potential exploitation risks. The vulnerabilities could allow for excessive processing, leading to service disruptions. The updates can be installed via the 'dnf' update program. Fedora 43 and Fedora 44 users are impacted by these vulnerabilities. The issues have been resolved in the latest updates, with specific advisories issued for both versions.

Key Points: • Fedora updates SpoofDPI to fix CVE-2026-27145 affecting DNS SAN processing. • Denial of service vulnerability could lead to significant service disruptions. • Users are urged to upgrade using the 'dnf' update program to mitigate risks.

ThreatCluster AI

Timeline

2026-06-02
CVE-2026-27145 published
CVE-2026-27145 details a denial of service vulnerability in the golang crypto/x509 package.
Linuxsecurity
2026-06-03
First public PoC for CVE-2026-27145
Proof of concept for the denial of service vulnerability was made public, raising concerns over potential exploitation.
Linuxsecurity
2026-07-14
Fedora releases updates for SpoofDPI
Updates for SpoofDPI version 1.5.3 were released to fix CVE-2026-27145 and other issues.
Linuxsecurity
2026-07-14
Denial of service vulnerability confirmed
The denial of service vulnerability was confirmed affecting both Fedora 43 and 44 users.
Linuxsecurity
2026-07-18
Fedora advisory issued for SpoofDPI updates
Fedora issued advisories for users to upgrade SpoofDPI to mitigate the denial of service risk.
Linuxsecurity

Community

Browse all →