Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64193

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:"<command>"} in EXTRA-TEXT.

A flaw was found in Net::DNS. A remote attacker can exploit a vulnerability in the handling of EDNS (Extension Mechanisms for DNS) EXTENDED ERROR options, leading to arbitrary code execution. The affected component processes the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option without properly escaping special characters, which allows for command injection. This enables an attacker to execute unauthorized commands on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perl-Net-DNSNot affected
Red Hat Enterprise Linux 7perl-Net-DNSNot affected
Red Hat Enterprise Linux 8perl-Net-DNSNot affected
Red Hat Enterprise Linux 9perl-Net-DNSNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2502954Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling

EPSS

Процентиль: 54%
0.00828
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
13 дней назад

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

CVSS3: 9.8
nvd
13 дней назад

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

CVSS3: 9.8
debian
13 дней назад

Net::DNS versions through 1.55 for Perl allow remote execution injecti ...

CVSS3: 9.8
github
13 дней назад

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

suse-cvrf
11 дней назад

Security update for perl-Net-DNS

EPSS

Процентиль: 54%
0.00828
Низкий

9.8 Critical

CVSS3