next-20260828: linux-next
Version:next-20260828 (linux-next)
Released:2026-08-28
Rebase to OpenSSL 4.0.2
Rebase to OpenSSL 3.5.8
Rebase to OpenSSL 3.5.8
Update to 1.75.0
BUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txtBUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txtBUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txtBUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txtBUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txtBUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txtBUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt