Security update for coredns
This update for coredns fixes the following issues: Changes in coredns: - Update to version 1.14.2: * plugin/reload: Allow disabling jitter with 0s * bump deps * plugin/forward: fix parsing error when handling TLS+IPv6 address * plugin/loop: use crypto/rand for query name generation * plugin: reorder rewrite before acl to prevent bypass * fix(rewrite): fix cname target rewrite for CNAME chains * fix(kubernetes): panic on empty ListenHosts * chore: bump minimum Go version to 1.25 * feat(proxyproto): add proxy protocol support * refactor(cache): modernize with generics * Add metadata for response Type and Class to Log * docs: clarify kubernetes auth docs * fix: return SOA and NS records when queried for a record CNAMEd to origin - fixes bsc#1259320 CVE-2026-26017 - fixes bsc#1259319 CVE-2026-26018 - address more unstable unstable tests under aarch64 and s390x - Update to version 1.14.1: * This release primarily addresses security vulnerabilities affecting Go versions prior to Go 1.25.6 and Go 1.24.12 (CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2025-61731, CVE-2025-68119). It also includes performance improvements to the proxy plugin via multiplexed connections, along with various documentation updates.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for coredns fixes the following issues: Changes in coredns: - Update to version 1.14.2: * plugin/reload: Allow disabling jitter with 0s * bump deps * plugin/forward: fix parsing error when handling TLS+IPv6 address * plugin/loop: use crypto/rand for query name generation * plugin: reorder rewrite before acl to prevent bypass * fix(rewrite): fix cname target rewrite for CNAME chains * fix(kubernetes): panic on empty ListenHosts * chore: bump minimum Go version to 1.25 * feat(proxyproto): add proxy protocol support * refactor(cache): modernize with generics * Add metadata for response Type and Class to Log * docs: clarify kubernetes auth docs * fix: return SOA and NS records when queried for a record CNAMEd to origin - fixes bsc#1259320 CVE-2026-26017 - fixes bsc#1259319 CVE-2026-26018 - address more unstable unstable tests under aarch64 and s390x - Update to version 1.14.1: * This release primarily addresses security vulnerabilities affecting Go versions prior to Go 1.25.6 and Go 1.24.12 (CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, CVE-2025-61731, CVE-2025-68119). It also includes performance improvements to the proxy plugin via multiplexed connections, along with various documentation updates.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1259319
- https://bugzilla.suse.com/1259320
- https://www.suse.com/security/cve/CVE-2025-61726
- https://www.suse.com/security/cve/CVE-2025-61728
- https://www.suse.com/security/cve/CVE-2025-61731
- https://www.suse.com/security/cve/CVE-2025-68119
- https://www.suse.com/security/cve/CVE-2025-68121
- https://www.suse.com/security/cve/CVE-2026-26017
- https://www.suse.com/security/cve/CVE-2026-26018