CVE-2026-93657

NameCVE-2026-93657
Descriptionhickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-hickory-resolver (PTS)trixie0.24.4-1vulnerable
forky, sid0.26.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-hickory-resolversource(unstable)0.26.3-1

Notes

[trixie] - rust-hickory-resolver <no-dsa> (Minor issue)
https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6
https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238

Search for package or bug name: Reporting problems