TEMP-0000000-040C76

NameTEMP-0000000-040C76
DescriptionDNS-over-QUIC heap buffer overflow (RCE)
SourceAutomatically generated temporary name. Not for external reference.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
knot-resolver (PTS)bullseye5.3.1-1+deb11u1vulnerable
bookworm, bookworm (security)5.6.0-1+deb12u1vulnerable
trixie5.7.5-1vulnerable
forky, sid6.4.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
knot-resolversource(unstable)6.4.1-1

Notes

https://www.openwall.com/lists/oss-security/2026/07/23/6
https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/

Search for package or bug name: Reporting problems