Resource exhaustion in dnsdist - CVE-2025-30187

 

Resource exhaustion in dnsdist - CVE-2025-30187

Published: September 19, 2025


Vulnerability identifier: #VU115968
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30187
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the nghttp2 library when handling incoming DNS over HTTPS queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

dnsdist
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Basesystem Module
Ubuntu
dnsdist (Ubuntu package)
dnsdist
dnsdist-debugsource
dnsdist-debuginfo

How to mitigate CVE-2025-30187

Install updates from vendor's website.

dnsdist - addressed in versions 1.9.11, 2.0.1
dnsdist (Ubuntu package) - addressed in versions 1.6.1-1ubuntu0.1~esm2, 1.8.3-2ubuntu0.1~esm1, 1.9.10-1ubuntu0.1
dnsdist - addressed in versions 1.9.11-1.el9, 1.9.11-1.fc41, 1.9.11-1.fc42, 1.9.11-2.el8, 2.0.1-1.el10_2, 2.0.1-1.fc43
dnsdist-debugsource - update to 1.9.11-150700.3.6.1
dnsdist-debuginfo - update to 1.9.11-150700.3.6.1
dnsdist - update to 1.9.11-150700.3.6.1

External References

Related Security Bulletins