SUSE Security Updates Address Moderate Vulnerabilities in perl-URI and perl-Net-DNS

SUSE Security Updates Address Moderate Vulnerabilities in perl-URI and perl-Net-DNS

First seen 9 Sep 2026, 14:44 UTC Linuxsecurity 45.0

Article Content

Browse articles
ThreatCluster

SUSE has released updates addressing two moderate vulnerabilities in its software packages perl-URI and perl-Net-DNS. The perl-URI update resolves CVE-2026-19953, which involves non-NFC host names encoded to non-standard punycode labels due to a normalization issue. This vulnerability affects multiple SUSE Linux Enterprise products, including Server and Desktop versions. The perl-Net-DNS update fixes CVE-2026-81928, a memory exhaustion issue caused by unbounded recursion when handling TSIG records. Both vulnerabilities are rated moderate in severity, with CVE-2026-19953 having a CVSS score of 6.5 and CVE-2026-81928 scoring 7.5. Administrators are advised to apply the patches using SUSE's recommended installation methods. The updates were released on September 7 and September 8, 2026, respectively. No active exploitation has been reported for either vulnerability.

Key Points: • SUSE released updates for moderate vulnerabilities in perl-URI and perl-Net-DNS. • CVE-2026-19953 affects host name normalization in perl-URI, while CVE-2026-81928 involves memory exhaustion. • Administrators are urged to apply patches using SUSE's recommended methods.

Ask AI about this cluster

Timeline

2026-08-31
CVE-2026-19953 published
SUSE disclosed a vulnerability in perl-URI affecting host name normalization, impacting various SUSE products.
Linuxsecurity
2026-09-01
CVE-2026-81928 published
SUSE disclosed a memory exhaustion vulnerability in perl-Net-DNS caused by unbounded recursion.
Linuxsecurity
2026-09-07
perl-URI patch released
SUSE released an update to fix CVE-2026-19953, urging users to apply the patch immediately.
Linuxsecurity
2026-09-08
perl-Net-DNS patch released
SUSE released an update for perl-Net-DNS addressing CVE-2026-81928, recommending immediate application.
Linuxsecurity