Double free in dnsdist - CVE-2025-30194
Published: April 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error when DNSdist is configured to provide DoH via the nghttp2 provider. A remote attacker can initiate a crafted DoH exchange that triggers an illegal memory access and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Fedora
dnsdist
dnsdist-debuginfo
dnsdist-debugsource
How to mitigate CVE-2025-30194
dnsdist - addressed in versions 1.9.9-1.fc40, 1.9.9-1.fc41, 1.9.9-1.fc42
dnsdist-debuginfo - update to 1.9.10-150700.3.3.1
dnsdist-debugsource - update to 1.9.10-150700.3.3.1
dnsdist - update to 1.9.10-150700.3.3.1