Information on source package dnsdist

Available versions

ReleaseVersion
bookworm1.7.3-2
trixie1.9.15-0+deb13u1
trixie (security)1.9.16-0+deb13u1
forky2.1.1-1
sid2.1.1-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-52682vulnerablefixedfixedfixedA crafted DNS packet can cause increased memory and CPU consumption
CVE-2026-42005vulnerablefixedfixedfixedAn attacker can send a web request that causes unlimited memory alloc ...
CVE-2026-42004vulnerablefixedfixedfixedAn attacker can send a crafted EDNS OPT record that will be ignored by ...
CVE-2026-40211vulnerablefixedfixedfixedAn attacker can send crafted DNS over HTTP/3 queries, triggering an ex ...
CVE-2026-40210vulnerablefixedfixedfixedAn out-of-bounds read might happen when SetMacAddrAction is used, pote ...
CVE-2026-40209vulnerablefixedfixedfixedAn attacker might be able to cause outgoing TCP connections to backend ...
CVE-2026-40208vulnerablefixedfixedfixedAn attacker might be able to delay the processing of DoH3 queries by s ...
CVE-2026-40011vulnerablefixedfixedfixedAn attacker sending a large number of crafted DNS queries might be abl ...
CVE-2026-33602vulnerablefixedfixedfixedA rogue backend can send a crafted UDP response with a query ID off by ...
CVE-2026-33599vulnerablefixedfixedfixedA rogue backend can send a crafted SVCB response to a Discovery of Des ...
CVE-2026-33598vulnerablefixedfixedfixedA cached crafted response can cause an out-of-bounds read if custom Lu ...
CVE-2026-33597vulnerablefixedfixedfixedPRSD detection denial of service
CVE-2026-33596vulnerablefixedfixedfixedA client might theoretically be able to cause a mismatch between queri ...
CVE-2026-33595vulnerablefixedfixedfixedA client can trigger excessive memory allocation by generating a lot o ...
CVE-2026-33594vulnerablefixedfixedfixedA client can trigger excessive memory allocation by generating a lot o ...
CVE-2026-33593vulnerablefixedfixedfixedA client can trigger a divide by zero error leading to crash by sendin ...
CVE-2026-33260vulnerablefixedfixedfixedAn attacker can send a web request that causes unlimited memory alloca ...
CVE-2026-33257vulnerablefixedfixedfixedAn attacker can send a web request that causes unlimited memory alloca ...
CVE-2026-33254vulnerablefixedfixedfixedAn attacker can create a large number of concurrent DoQ or DoH3 connec ...
CVE-2026-27854vulnerablefixedfixedfixedAn attacker might be able to trigger a use-after-free by sending craft ...
CVE-2026-27853vulnerablefixedfixedfixedAn attacker might be able to trigger an out-of-bounds write by sending ...
CVE-2026-24030vulnerablefixedfixedfixedAn attacker might be able to trick DNSdist into allocating too much me ...
CVE-2026-24029vulnerablefixedfixedfixedWhen the early_acl_drop (earlyACLDrop in Lua) option is disabled (defa ...
CVE-2026-24028vulnerablefixedfixedfixedAn attacker might be able to trigger an out-of-bounds read by sending ...
CVE-2026-0397vulnerablefixedfixedfixedWhen the internal webserver is enabled (default is disabled), an attac ...
CVE-2026-0396vulnerablefixedfixedfixedAn attacker might be able to inject HTML content into the internal web ...
CVE-2025-30193vulnerablefixedfixedfixedIn some circumstances, when DNSdist is configured to allow an unlimite ...
CVE-2023-44487vulnerablefixedfixedfixedThe HTTP/2 protocol allows a denial of service (server resource consum ...

Resolved issues

BugDescription
CVE-2025-30194When DNSdist is configured to provide DoH via the nghttp2 provider, an ...
CVE-2025-30187In some circumstances, when DNSdist is configured to use the nghttp2 l ...
CVE-2024-25581When incoming DNS over HTTPS support is enabled using the nghttp2 prov ...
CVE-2018-14663An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a re ...
CVE-2017-7557dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechan ...
CVE-2016-7069An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT r ...

Security announcements

DSA / DLADescription
DSA-6419-1dnsdist - security update
DSA-6367-1dnsdist - security update
DSA-6235-1dnsdist - security update

Search for package or bug name: Reporting problems