Linuxsecurity
SUSE Security Updates Address Moderate Vulnerabilities in perl-URI and perl-Net-DNS
Article Content
SUSE has released updates addressing two moderate vulnerabilities in its software packages perl-URI and perl-Net-DNS. The perl-URI update resolves CVE-2026-19953, which involves non-NFC host names encoded to non-standard punycode labels due to a normalization issue. This vulnerability affects multiple SUSE Linux Enterprise products, including Server and Desktop versions. The perl-Net-DNS update fixes CVE-2026-81928, a memory exhaustion issue caused by unbounded recursion when handling TSIG records. Both vulnerabilities are rated moderate in severity, with CVE-2026-19953 having a CVSS score of 6.5 and CVE-2026-81928 scoring 7.5. Administrators are advised to apply the patches using SUSE's recommended installation methods. The updates were released on September 7 and September 8, 2026, respectively. No active exploitation has been reported for either vulnerability.
Key Points: • SUSE released updates for moderate vulnerabilities in perl-URI and perl-Net-DNS. • CVE-2026-19953 affects host name normalization in perl-URI, while CVE-2026-81928 involves memory exhaustion. • Administrators are urged to apply patches using SUSE's recommended methods.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.