Ubuntu alert USN-8449-1 (ldns)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8449-1] ldns vulnerability | |
| Date: | Thu, 18 Jun 2026 14:38:22 +0000 | |
| Message-ID: | <E1waDss-0006Pt-Pg@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8449-1 June 18, 2026 ldns vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: ldns could be made to accept spoofed DNS responses. Software Description: - ldns: ldns library for DNS programming Details: Pablo Ruiz discovered that ldns did not properly validate DNS responses when used as a stub resolver over UDP. A remote attacker could possibly use this issue to inject arbitrary DNS responses. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS ldnsutils 1.8.4-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro libldns3t64 1.8.4-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS ldnsutils 1.8.3-2ubuntu0.1~esm1 Available with Ubuntu Pro libldns3t64 1.8.3-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS ldnsutils 1.7.1-2ubuntu4+esm2 Available with Ubuntu Pro libldns3 1.7.1-2ubuntu4+esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS ldnsutils 1.7.0-4.1ubuntu1+esm2 Available with Ubuntu Pro libldns2 1.7.0-4.1ubuntu1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS ldnsutils 1.7.0-3ubuntu4.1+esm1 Available with Ubuntu Pro libldns2 1.7.0-3ubuntu4.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS ldnsutils 1.6.17-8ubuntu0.1+esm2 Available with Ubuntu Pro libldns1 1.6.17-8ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8449-1 CVE-2026-10846
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo0AgAACgkQcpJm3tlz hgF4bRAAp/cuC4RJakVZNBDVroTCToaVXaOhqzq0I1UaVeSP4ilVVSAvEOhlQScI 08gy4qS7il58zxga3cNOapDaeQLYKWtA/CA8wgpdvYYqZiJy+5HBj3jLiylt+Ubt XVokUsd2SGp9/H/mWK6Z0ZU9L+C8qSXQEOcxZZbVbENugGX6JY94enN52PlIsxQy xG7kTtR7Plcfp1agOCy4TmQtgDEm3stwaH/V3NYzfx8HC5cCpwDpsv9iiwz/C+hh kltYhP/DZMzaseBL5x6F2EBVMGrmTy7I8EOiAQgeOCPUNlq8inza8HWsxAGTJved Pm6u3i9uZXoZGa2WVuwP6krHa3/eOp4lDNzTUzNPFCMshPsTxAfByFfBhVbQL+sI bIR708/nNfCNKjdxrQEqBV647Vk+0cI4vcMnA5QbpM8stp+j3WjTV+Ym7fdyr1Zc 7TkTVRUSq/p9VDO1LQAdZRT6QTCPSagxkbCu3Hc6MxFvNPXdRIurdo0FIGEnbXwz qvDgHwtCEGfB5Iau8yGRtvFgZm3qhLaAJs2Me2fszCq/zVseJiinDFQCf1EepeYi zLBKYXZinAYmI4feTR2xDWZD8xEA54/y/6tgsbS4ZDKv9StpoQR3aic2AtxbqIyy 9NdfhjE7dk9KH19Hf/zgmArTaa4xKkDvn9vUYN96Zy7eLqmbQj4= =lKPM -----END PGP SIGNATURE-----
