Uncontrolled Memory Allocation in dnsdist - CVE-2026-24030
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in DNS over QUIC and DNS over HTTP/3 payload processing when handling DoQ or DoH3 queries. A remote attacker can send DoQ or DoH3 queries to cause a denial of service.
In some environments the condition results in an exception and connection closure, but in others it might lead to an out-of-memory state and process termination.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Basesystem Module
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
dnsdist (Debian package)
How to mitigate CVE-2026-24030
dnsdist - addressed in versions 1.9.12-1.el8, 1.9.12-1.el9, 1.9.12-1.fc42, 2.0.3-1.el10_3, 2.0.3-1.fc43, 2.0.3-1.fc44
dnsdist-debugsource - update to 1.9.12-150700.3.9.1
dnsdist-debuginfo - update to 1.9.12-150700.3.9.1
dnsdist - update to 1.9.12-150700.3.9.1
dnsdist (Debian package) - update to 1.9.14-0+deb13u1