Double free in dnsdist - CVE-2025-30194

 

Double free in dnsdist - CVE-2025-30194

Published: April 29, 2025


Vulnerability identifier: #VU108042
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30194
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a double free error when DNSdist is configured to provide DoH via the nghttp2 provider. A remote attacker can initiate a crafted DoH exchange that triggers an illegal memory access and perform a denial of service (DoS) attack.




Affected software

dnsdist
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Fedora
dnsdist
dnsdist-debuginfo
dnsdist-debugsource

How to mitigate CVE-2025-30194

Install updates from vendor's website.

dnsdist - update to 1.9.9
dnsdist - addressed in versions 1.9.9-1.fc40, 1.9.9-1.fc41, 1.9.9-1.fc42
dnsdist-debuginfo - update to 1.9.10-150700.3.3.1
dnsdist-debugsource - update to 1.9.10-150700.3.3.1
dnsdist - update to 1.9.10-150700.3.3.1

External References

Related Security Bulletins