CVE-2026-52684

NameCVE-2026-52684
DescriptionIf the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pdns-recursor (PTS)bullseye4.4.2-3vulnerable
bookworm, bookworm (security)4.8.8-1+deb12u1vulnerable
trixie5.2.11-0+deb13u1vulnerable
trixie (security)5.2.12-0+deb13u1vulnerable
forky5.4.3-1vulnerable
sid5.4.4-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pdns-recursorsourcebullseye(unfixed)end-of-life
pdns-recursorsourcebookworm(unfixed)end-of-life
pdns-recursorsource(unstable)(unfixed)

Notes

[trixie] - pdns-recursor <no-dsa> (Minor issue)
[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
https://github.com/PowerDNS/pdns/pull/17748
Fixed by: https://github.com/PowerDNS/pdns/commit/63f480d2072d85ff5cd6eeb324bd52bf5debd4f7

Search for package or bug name: Reporting problems