Dear Stable Release Managers
This is late for 13.7, but please consider it for 13.8.
libnet-dns-perl is affected by CVE-2026-81928, an unbound recursion
when re-encoding message with misplaced TSIG, which may result in
denial of service. We classified it as no-dsa, but it would be good to
have it fixed in trixie as well.
I opted here again to import the new upstream version, which
additionally contains:
- Resync with IANA DNS parameters registry.
- EDNS: Add support for MQTYPE-QUERY option.
- UNIX resolver can fail in taint mode
I already followed upstream recommendatation for the previous import,
which was released as DSA, so we had a bump from 1.50-1 in trixie to
1.56-0+deb13u1 and so now followed by 1.57-0+deb13u1.
Attached is only the debdiff beween the last security update and the
1.57-0+deb13u1 one.
Regards,
Salvatore