ELA-1815-1 libnet-dns-perl security update

denial of service

2026-08-30
Packagelibnet-dns-perl
Version1.07-1+deb9u1 (stretch), 1.19-1+deb10u1 (buster)
Related CVEs CVE-2026-64194


Steffen Ullrich discovered that the Net::DNS::DomainName::decode() routine followed RFC 1035 compression pointers by recursing into itself without any depth limit, thereby allowing Denial of Service via crafted packet.



For Debian 10 buster, these problems have been fixed in version 1.19-1+deb10u1.

For Debian 9 stretch, these problems have been fixed in version 1.07-1+deb9u1.

We recommend that you upgrade your libnet-dns-perl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.