stable

dnsdist-2.0.6-1.fc44

FEDORA-2026-51cdd1292b created by filiperosset 3 months ago for Fedora 44

Bug Fixes:

CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default

CVE-2026-33257: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default

CVE-2026-33260: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default

CVE-2026-33593: A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query

CVE-2026-33595: A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection. DOQ and DoH3 are disabled by default

CVE-2026-33596: A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend

CVE-2026-33597: A crafted query containing an invalid DNS label can prevent the PRSD detection algorithm executed via DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI from being executed

CVE-2026-33598: A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache

CVE-2026-33599: A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default

CVE-2026-33602: A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service

CVE-2026-33594: A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection. Outgoing DoH is disabled by default

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-51cdd1292b

This update has been submitted for testing by filiperosset.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago

This update has been submitted for stable by bodhi.

3 months ago

filiperosset edited this update.

3 months ago

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

Metadata
Type
security
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
3 months ago
modified
3 months ago
approved
3 months ago
BZ#2460830 CVE-2026-33260 dnsdist: insufficient input validation of internal webserver [epel-all]
0
0
BZ#2460831 CVE-2026-33260 dnsdist: insufficient input validation of internal webserver [fedora-all]
0
0
BZ#2460832 CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [epel-all]
0
0
BZ#2460833 CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [fedora-all]
0
0
BZ#2460834 CVE-2026-33596 dnsdist: TCP backend stream ID overflow [epel-all]
0
0
BZ#2460835 CVE-2026-33596 dnsdist: TCP backend stream ID overflow [fedora-all]
0
0
BZ#2460836 CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [epel-all]
0
0
BZ#2460837 CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [fedora-all]
0
0
BZ#2460838 CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [epel-all]
0
0
BZ#2460839 CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [fedora-all]
0
0
BZ#2460840 CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [epel-all]
0
0
BZ#2460841 CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [fedora-all]
0
0
BZ#2460842 CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [epel-all]
0
0
BZ#2460843 CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [fedora-all]
0
0
BZ#2460844 CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [epel-all]
0
0
BZ#2460845 CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [fedora-all]
0
0
BZ#2460846 CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [epel-all]
0
0
BZ#2460847 CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [fedora-all]
0
0
BZ#2460848 CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [epel-all]
0
0
BZ#2460849 CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [fedora-all]
0
0
BZ#2460851 CVE-2026-33593 dnsdist: denial of service via crafted DNSCrypt query [fedora-all]
0
0

Automated Test Results