CVE-2025-30194

NameCVE-2025-30194
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1104351

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dnsdist (PTS)bullseye1.5.1-3fixed
bookworm1.7.3-2fixed
trixie1.9.8-1vulnerable
sid1.9.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dnsdistsourcebullseye(not affected)
dnsdistsourcebookworm(not affected)
dnsdistsource(unstable)1.9.9-11104351

Notes

[bookworm] - dnsdist <not-affected> (Introduced in 1.9.0)
[bullseye] - dnsdist <not-affected> (Introduced in 1.9.0)
https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2025-02.html
https://github.com/PowerDNS/pdns/issues/15475
Fixed by: https://github.com/PowerDNS/pdns/commit/954eb1921699147b16f8bcd08029e37da3e789b9 (master)
https://github.com/PowerDNS/pdns/pull/15482
Fixed by: https://github.com/PowerDNS/pdns/commit/68edfd9be00f18101216eb394e3b18bd6feb77f4 (dnsdist-1.9.9)

Search for package or bug name: Reporting problems