freenode

← digests

DNS and kernel security disclosures

Security & Cryptography2026-07-23

Major DNS implementations and the Linux kernel saw multiple vulnerability disclosures and patches, spanning privilege escalations, cache issues, and denial of service. Mail and logging software also received targeted fixes that operators should evaluate for urgency.

ISC discloses nine BIND 9 vulnerabilities

The Internet Systems Consortium disclosed nine vulnerabilities in BIND 9 under CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, and CVE-2026-13321. The flaws affect DNSSEC validation, caching, and stability. Operators of authoritative or recursive BIND servers should apply the corresponding updates to limit exposure.

Qualys reports XFS reflink LPE race

Qualys disclosed a local privilege escalation via a race condition in the Linux kernel XFS reflink path, tracked as CVE-2026-64600 and found with AI assistance. Red Hat published a SystemTap based mitigation. Systems that enable XFS reflink remain at risk of local escalation until the kernel fix is deployed.

Unbound 1.25.2 closes eight CVEs

Unbound 1.25.2 was released to address eight CVEs, four of them rated HIGH. The issues include denial of service, cache poisoning, and overflows along QUIC and DNSCrypt code paths. Recursive resolver operators should upgrade to close these vectors.

Heap OOB write LPE in Linux UDP corking

Two CVEs (CVE-2026-53362 and CVE-2026-53366) were publicly detailed for an exploitable heap out of bounds write in Linux kernel UDP MSG_SPLICE_PAGES fragment boundary handling. The flaws affect kernels from v6.1 onward and come with published exploits. Unpatched hosts face practical local privilege escalation risk.

Kernel CNA assigns 432 CVEs in 31 hours

The Linux kernel CNA assigned 432 CVEs within a 31 hour window. The volume prompted discussion on oss-security about whether individual CVE prioritization remains practical. Distributors and administrators face growing triage pressure under this disclosure rate.

Exim 4.99.5 fixes directory traversal

Exim 4.99.5 corrects a local directory traversal reachable through command line access that enables privilege escalation. The bug has been present in all releases since 4.88. Mail transfer agent operators should upgrade to remove the local escalation path.

Roundcube patches XSS, SSRF and related flaws

Roundcube 1.6.17 and 1.7.2 fix multiple XSS, SSRF, denial of service, and TNEF issues, including CVE-2026-54432 and others. The updates close both client side and server side attack surfaces. Hosts running the webmail package should move to the new releases.

rsyslog imptcp regex framing DoS

rsyslog versions v8.36.0 through v8.2606.0 contain a remote denial of service in the optional imptcp regex framing feature, scored CVSS 7.5 and configuration dependent. The feature has been non default since introduction. Only deployments that explicitly enable it need the corrective release.