CoreDNS
v1.14.7Kubernetes Core2026年8月19日
セキュリティ関連の依存関係更新と、ACLチェックを回避できる問題の修正が含まれます。運用時に見える既定値の変更に加え、多数の機能追加、挙動変更、不具合修正があります。
要対応 (1)
securityhigh
Go 1.によるCVE修正の取り込み26. 6 ビルドに
Go 1.を使用し、CVE-2026-56865、CVE-2026-56864、CVE-2026-33818 の修正を取り込んでいます。26. 6
影響確認 (3)
security
autopathによるACLチェック回避の修正plugin/aclとautopathを使用している場合に適用されます。plugin/aclで、autopathがACLチェックを回避していた問題を修正しました。breaking
plugin/forwardの接続試行回数の既定上限適用対象はリリースノートに明記されていません。
plugin/forwardの接続試行回数に既定の上限を設けました。breaking
plugin/hostsの未対応typeに対するfallthroughの既定動作変更適用対象はリリースノートに明記されていません。
plugin/hostsで、未対応のtypeをfallthroughさせる動作をオプトインに変更しました。
その他の記録済み変更 42 件すべてvalue changes 16 · fixes 13 · additions 11 · constraints 2
value changes (16)
- core: Normalize server block zones (https://github.com/coredns/coredns/pull/8320)
- core: Pin numeric uid/gid for the nonroot user (https://github.com/coredns/coredns/pull/8316)
- plugin/cache: Bind responses and entries to QCLASS (https://github.com/coredns/coredns/pull/8272)
- plugin/cache: Do not cache SOA-less NODATA responses (https://github.com/coredns/coredns/pull/8232)
- plugin/cache: Preserve AD when storing cache entries (https://github.com/coredns/coredns/pull/8438)
- plugin/cache: Preserve monotonic time for TTL expiry (https://github.com/coredns/coredns/pull/8346)
- plugin/file: Do not expand wildcard across a closer empty non-terminal (https://github.com/coredns/coredns/pull/8223)
- plugin/file: Resolve each additional section target only once (https://github.com/coredns/coredns/pull/8286)
- plugin/file: Return referrals after alias resolution (https://github.com/coredns/coredns/pull/8341)
- plugin/file: Run additional processing for CNAME/DNAME answers (https://github.com/coredns/coredns/pull/8337)
- plugin/forward: Fast-path string comparison in isAllowedDomain (https://github.com/coredns/coredns/pull/8385)
- plugin/kubernetes: Copy Labels in Pod.DeepCopyObject (https://github.com/coredns/coredns/pull/8415)
- plugin/kubernetes: Short-circuit matchPortAndProtocol and fast-path string match (https://github.com/coredns/coredns/pull/8344)
- plugin/kubernetes: Skip zone serial bump on DNS neutral pod updates (https://github.com/coredns/coredns/pull/8338)
- plugin/proxyproto: Apply an explicitly configured default policy evenwhen no allow list is present. (https://github.com/coredns/coredns/pull/8278)
- plugin/rewrite: Preserve original request during rewrites (https://github.com/coredns/coredns/pull/8235)
fixes (13)
- plugin/acl: Fix blocked clients from receiving cached DNS answers (https://github.com/coredns/coredns/pull/8289)
- plugin/auto: Fix inverted arguments in duplicate-origin warning (https://github.com/coredns/coredns/pull/8317)
- plugin/cache: Fix cache stale verification metadata race (https://github.com/coredns/coredns/pull/8366)
- plugin/file: Fixes multi-primary AXFR zone contamination (https://github.com/coredns/coredns/pull/8367)
- plugin/file: Fix panic on zero-valued SOA refresh (https://github.com/coredns/coredns/pull/8276)
- plugin/file: Stop self-referential DNAME loops (https://github.com/coredns/coredns/pull/8418)
- plugin/forward: Fix incorrect failover counter reset (https://github.com/coredns/coredns/pull/8277)
- plugin/forward: Fix incorrect retry of local DNS message serialization failures (https://github.com/coredns/coredns/pull/8313)
- plugin/forward: Fix issue in DoH health checks used a default TLS instead of the configured CA (https://github.com/coredns/coredns/pull/8279)
- plugin/forward: Fix UDP forwarding so a malformed upstream datagram wont block valid ones later (https://github.com/coredns/coredns/pull/8287)
- plugin/rewrite: Normalize exact cname rewrite targets and preserve all records (https://github.com/coredns/coredns/pull/8285)
- plugin/secondary: Reset catalog members on ID change (https://github.com/coredns/coredns/pull/8281)
- plugin/transfer: Collect all notify errors instead of shadowing (https://github.com/coredns/coredns/pull/8283)
additions (11)
- core: Add connection-level concurrency limiting to DNS-over-QUIC (https://github.com/coredns/coredns/pull/8213)
- core: Add max conn limit to https3 (https://github.com/coredns/coredns/pull/8187)
- plugin/cache: Add prefer_positive stale policy (https://github.com/coredns/coredns/pull/8378)
- plugin/cache: Configure stale TTL and failure recheck (https://github.com/coredns/coredns/pull/8411)
- plugin/file: Handle empty non-terminal wildcard sources (https://github.com/coredns/coredns/pull/8386)
- plugin/forward: Add http(2) host/authority header and TO server resolution (https://github.com/coredns/coredns/pull/8233)×2
- plugin/secondary: Support catalog migration and member scoping (https://github.com/coredns/coredns/pull/8288)
- plugin/shed: Add UDP overload protection plugin (https://github.com/coredns/coredns/pull/8312)
- plugin/timeouts: Add maxtcpqueries option to bound queries per TCP/TLS connection (https://github.com/coredns/coredns/pull/8376)
- plugin/tls: Manage certificates with ACME DNS-01 (https://github.com/coredns/coredns/pull/8310)
constraints (2)
- plugin/kubernetes: Add support for topology-aware headless services via "az-pinned" subdomains (https://github.com/coredns/coredns/pull/8388)
- plugin/trace: Support IPv6 service endpoints in trace plugin (https://github.com/coredns/coredns/pull/8410)
CoreDNSをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチと破壊的変更も、その一例です。