#VU108042 Double free in dnsdist - CVE-2025-30194
Published: April 29, 2025
dnsdist
PowerDNS.COM B.V.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error when DNSdist is configured to provide DoH via the nghttp2 provider. A remote attacker can initiate a crafted DoH exchange that triggers an illegal memory access and perform a denial of service (DoS) attack.