SB20251022166 - DNS cache poisoning in PowerDNS Recursor
Published: October 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Insufficient verification of data authenticity (CVE-ID: CVE-2025-59023)
The vulnerability allows a remote attacker to poison DNS cache.
The vulnerability exists due to software does not apply strict enough validation of received delegation information. A remote attacker can spoof delegation requests and poison DNS cache of the server.
2) Insufficient verification of data authenticity (CVE-ID: CVE-2025-59024)
The vulnerability allows a remote attacker to poison DNS cache.
The vulnerability exists due to software does not apply strict enough validation of received delegation information. A remote attacker can use an UDP IP fragments attack to poison DNS cache of the server.
Remediation
Install update from vendor's website.