Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42004

Опубликовано: 25 июн. 2026
Источник: debian
EPSS Низкий

Описание

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsdistfixed2.1.0-1package
dnsdistend-of-lifebookwormpackage
dnsdistend-of-lifebullseyepackage

Примечания

  • https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html#cve-2026-42004-edns-options-smuggling

EPSS

Процентиль: 5%
0.00156
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

CVSS3: 3.7
nvd
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

CVSS3: 3.7
github
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

suse-cvrf
11 дней назад

Security update for dnsdist

EPSS

Процентиль: 5%
0.00156
Низкий