Resource exhaustion in dnsdist - CVE-2025-30187
Published: September 19, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the nghttp2 library when handling incoming DNS over HTTPS queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Basesystem Module
Ubuntu
dnsdist (Ubuntu package)
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
How to mitigate CVE-2025-30187
dnsdist (Ubuntu package) - addressed in versions 1.6.1-1ubuntu0.1~esm2, 1.8.3-2ubuntu0.1~esm1, 1.9.10-1ubuntu0.1
dnsdist - addressed in versions 1.9.11-1.el9, 1.9.11-1.fc41, 1.9.11-1.fc42, 1.9.11-2.el8, 2.0.1-1.el10_2, 2.0.1-1.fc43
dnsdist-debugsource - update to 1.9.11-150700.3.6.1
dnsdist-debuginfo - update to 1.9.11-150700.3.6.1
dnsdist - update to 1.9.11-150700.3.6.1