CVE-2026-39155

NameCVE-2026-39155
DescriptionKnot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
knot (PTS)bullseye3.0.5-1+deb11u1vulnerable
bookworm3.2.6-1vulnerable
trixie3.4.6-2vulnerable
forky3.5.5-1fixed
sid3.5.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
knotsource(unstable)3.5.4-1

Notes

https://www.knot-dns.cz/2026-04-01-version-3410.html
https://www.knot-dns.cz/2026-04-02-version-354.html

Search for package or bug name: Reporting problems