Executive brief
A vulnerability in the PowerDNS Recursor, a service used to translate human-readable domain names into IP addresses, could allow a malicious server to crash the system. By sending a specially crafted data zone, an attacker can trigger a service failure, leading to a denial of service for users relying on that DNS server. This impact is limited to service availability and does not involve data theft or unauthorized access.
Technical details
A denial of service vulnerability exists in PowerDNS Recursor's ZoneToCache function due to insufficient input validation in the zonemd.cc component. A malicious authoritative server can exploit this by sending a specially crafted zone, causing the Recursor process to crash. The attack requires the Recursor to be configured to fetch and cache zones from the attacker-controlled server. The vulnerability is addressed in versions 5.2.11, 5.3.8, and 5.4.3.
Affected products
- PowerDNS Recursor 5.2.0 to 5.2.10, 5.3.0 to 5.3.7, 5.4.0 to 5.4.2
Timeline
- 2026-06-25: disclosed: Initial advisory publication