Home / mailings [USN-8449-1] ldns vulnerability
Posted on 18 June 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8449-1
June 18, 2026
ldns vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
ldns could be made to accept spoofed DNS responses.
Software Description:
- ldns: ldns library for DNS programming
Details:
Pablo Ruiz discovered that ldns did not properly validate DNS
responses when used as a stub resolver over UDP. A remote
attacker could possibly use this issue to inject arbitrary DNS
responses.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
ldnsutils 1.8.4-2ubuntu0.26.04.1~esm1
Available with Ubuntu Pro
libldns3t64 1.8.4-2ubuntu0.26.04.1~esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
ldnsutils 1.8.3-2ubuntu0.1~esm1
Available with Ubuntu Pro
libldns3t64 1.8.3-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
ldnsutils 1.7.1-2ubuntu4+esm2
Available with Ubuntu Pro
libldns3 1.7.1-2ubuntu4+esm2
Available with Ubuntu Pro
Ubuntu 20.04 LTS
ldnsutils 1.7.0-4.1ubuntu1+esm2
Available with Ubuntu Pro
libldns2 1.7.0-4.1ubuntu1+esm2
Available with Ubuntu Pro
Ubuntu 18.04 LTS
ldnsutils 1.7.0-3ubuntu4.1+esm1
Available with Ubuntu Pro
libldns2 1.7.0-3ubuntu4.1+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
ldnsutils 1.6.17-8ubuntu0.1+esm2
Available with Ubuntu Pro
libldns1 1.6.17-8ubuntu0.1+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8449-1
CVE-2026-10846
--===============5892913497219359052==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
