Insufficient verification of data authenticity in FreeBSD - CVE-2026-10846
Published: June 11, 2026
FreeBSD
Detailed vulnerability description
The vulnerability allows a remote attacker to spoof DNS responses and inject arbitrary DNS data.
The vulnerability exists due to improper response validation in the ldns stub resolver when processing UDP DNS responses. A remote attacker can send a spoofed UDP response to spoof DNS responses and inject arbitrary DNS data.
The issue affects ldns when used as a stub resolver over UDP and can be exploited by an off-path adversary that cannot observe the original query.