Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71194

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

A flaw was found in the OpenStack Designate mDNS NOTIFY handler. The _handle_notify method performs zone lookups without pool_id scoping, unlike the QUERY and AXFR handlers which were previously updated to be pool-aware. When zones with the same name exist across different DNS pools, the storage layer finds multiple matches and raises a NotFound exception, causing all NOTIFY processing for the affected zone name to fail. This results in denial of service for DNS zone transfer notifications, causing stale zone data on secondary DNS servers. The mDNS NOTIFY path is reachable via unauthenticated UDP on port 5354.

Отчет

Red Hat OpenStack Platform (RHOSP) ships Designate across multiple versions. The mDNS NOTIFY handler DoS can occur whenever zone names collide across pools, regardless of how the colliding zones were created. However, in default configurations, only a single pool is used, making collisions unlikely without administrator action or exploitation of CVE-2026-71193. Multipool deployments using the AttributeFilter scheduler were never a fully supported configuration in any RHOSP version. In RHOSP 13, 16.2, and 17.1 (TripleO deployment), the mDNS service listens on port 5354/UDP by default and does not require authentication for the NOTIFY handler path. For Red Hat OpenStack Services on OpenShift (RHOSO, openstack-18.0), the mDNS service defaults to a ClusterIP service type with no NodePort or LoadBalancer exposure, making port 5354 reachable only within the OpenShift cluster network. This significantly limits the attack surface for the mDNS DoS.

Меры по смягчению последствий

Restrict network access to the mDNS service port (default 5354/UDP and TCP) using firewall rules, allowing only traffic from known DNS master servers. Note that enabling the 'query_enforce_tsig' option does NOT protect the NOTIFY handler path, as it only applies to QUERY and AXFR operations. To prevent the precondition of colliding zones: verify that the 'scheduler_filters' configuration option in the [service:central] section uses 'default_pool' (the default) or 'pool_id_attribute' instead of 'attribute'. This prevents unauthorized creation of zones in alternative pools.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-designateFix deferred
Red Hat OpenStack Platform 16.2openstack-designateFix deferred
Red Hat OpenStack Platform 17.1openstack-designateFix deferred
Red Hat OpenStack Platform 18.0openstack-designateFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2512060openstack-designate: designate: mDNS NOTIFY handler DoS via pool-blind zone lookup

EPSS

Процентиль: 41%
0.00509
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
19 дней назад

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

CVSS3: 6.8
nvd
19 дней назад

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

CVSS3: 6.8
debian
19 дней назад

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-b ...

CVSS3: 6.8
github
19 дней назад

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

EPSS

Процентиль: 41%
0.00509
Низкий

4.3 Medium

CVSS3