Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-52684

Опубликовано: 23 июл. 2026
Источник: debian
EPSS Низкий

Описание

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pdns-recursorunfixedpackage
pdns-recursorno-dsatrixiepackage
pdns-recursorend-of-lifebookwormpackage
pdns-recursorend-of-lifebullseyepackage

Примечания

  • https://github.com/PowerDNS/pdns/pull/17748

  • Fixed by: https://github.com/PowerDNS/pdns/commit/63f480d2072d85ff5cd6eeb324bd52bf5debd4f7

EPSS

Процентиль: 4%
0.00143
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
18 дней назад

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.

CVSS3: 3.7
nvd
18 дней назад

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.

CVSS3: 3.7
github
18 дней назад

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.

EPSS

Процентиль: 4%
0.00143
Низкий