Misinterpretation of Input in dnsdist - CVE-2026-42004
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass security rules.
The vulnerability exists due to improper neutralization of EDNS options in EDNS option filtering when processing crafted DNS queries with a crafted EDNS OPT record while EDNS Client Subnet is inserted. A remote attacker can send a crafted EDNS OPT record to bypass security rules.
The backend can receive EDNS options that were not filtered by DNSdist.
Affected software
Debian Linux
dnsdist (Debian package)
How to mitigate CVE-2026-42004
dnsdist (Debian package) - update to 1.9.15-0+deb13u1