NULL pointer dereference in PowerDNS Recursor - CVE-2026-33601
Published: April 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to null pointer dereference in zoneToCache ZONEMD record handling when processing a crafted zonemd record from a malicious authoritative server. A remote privileged user can send a crafted zonemd record to cause a denial of service.
Exploitation requires the zoneToCache function to be configured.
Affected software
Debian Linux
pdns-recursor (Debian package)
How to mitigate CVE-2026-33601
pdns-recursor (Debian package) - update to 5.2.9-0+deb13u1