stable

dnsdist-1.9.14-1.el8

FEDORA-EPEL-2026-d2905945db created by filiperosset 2 months ago for Fedora EPEL 8

Bug Fixes:

CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default

CVE-2026-33257: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default

CVE-2026-33260: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default

CVE-2026-33593: A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query

CVE-2026-33595: A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection. DOQ and DoH3 are disabled by default

CVE-2026-33596: A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend

CVE-2026-33597: A crafted query containing an invalid DNS label can prevent the PRSD detection algorithm executed via DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI from being executed

CVE-2026-33598: A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache

CVE-2026-33599: A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default

CVE-2026-33602: A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service

CVE-2026-33594: A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection. Outgoing DoH is disabled by default

This update has been submitted for testing by filiperosset.

2 months ago

This update's test gating status has been changed to 'ignored'.

2 months ago

This update has been pushed to testing.

2 months ago

This update has been submitted for stable by bodhi.

2 months ago

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
unspecified
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
2 months ago
in testing
2 months ago
in stable
a month ago
approved
2 months ago
BZ#2460830 CVE-2026-33260 dnsdist: insufficient input validation of internal webserver [epel-all]
0
0
BZ#2460831 CVE-2026-33260 dnsdist: insufficient input validation of internal webserver [fedora-all]
0
0
BZ#2460832 CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [epel-all]
0
0
BZ#2460833 CVE-2026-33257 dnsdist: insufficient input validation of internal webserver [fedora-all]
0
0
BZ#2460834 CVE-2026-33596 dnsdist: TCP backend stream ID overflow [epel-all]
0
0
BZ#2460835 CVE-2026-33596 dnsdist: TCP backend stream ID overflow [fedora-all]
0
0
BZ#2460836 CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [epel-all]
0
0
BZ#2460837 CVE-2026-33599 dnsdist: out-of-bounds read in service discovery [fedora-all]
0
0
BZ#2460838 CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [epel-all]
0
0
BZ#2460839 CVE-2026-33597 dnsdist: insufficient input validation of internal webserver [fedora-all]
0
0
BZ#2460840 CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [epel-all]
0
0
BZ#2460841 CVE-2026-33595 dnsdist: DoQ/DoH3 excessive memory allocation [fedora-all]
0
0
BZ#2460842 CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [epel-all]
0
0
BZ#2460843 CVE-2026-33594 dnsdist: outgoing DoH excessive memory allocation [fedora-all]
0
0
BZ#2460844 CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [epel-all]
0
0
BZ#2460845 CVE-2026-33602 dnsdist: off-by-one access when processing crafted UDP responses [fedora-all]
0
0
BZ#2460846 CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [epel-all]
0
0
BZ#2460847 CVE-2026-33254 dnsdist: resource exhaustion via DoQ/DoH3 connections [fedora-all]
0
0
BZ#2460848 CVE-2026-33598 dnsdist: out-of-bounds read in cache inspection via Lua [epel-all]
0
0

Automated Test Results