Use-after-free in PowerDNS Recursor - CVE-2026-33259
Published: April 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in RPZ data handling when processing many concurrent transfers of the same RPZ. A remote privileged user can trigger many concurrent transfers of the same RPZ to cause a denial of service.
Exploitation normally requires a malfunctioning RPZ provider.
Affected software
Debian Linux
pdns-recursor (Debian package)
How to mitigate CVE-2026-33259
pdns-recursor (Debian package) - update to 5.2.9-0+deb13u1