NIXPKGS-2025-0023
published on
Permalink
CVE-2025-59030
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
by @fricklerhandwerk Activity log
- Created automatic suggestion
- @fricklerhandwerk accepted
- @fricklerhandwerk published on GitHub
Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
Affected products
pdns-recursor
- <5.2.7
- <5.1.9
- <5.3.3
Package maintainers
-
@rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org>