Misinterpretation of Input in dnsdist - CVE-2026-42004

 

Misinterpretation of Input in dnsdist - CVE-2026-42004

Published: June 25, 2026


Vulnerability identifier: #VU135337
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42004
CWE-ID: CWE-115
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security rules.

The vulnerability exists due to improper neutralization of EDNS options in EDNS option filtering when processing crafted DNS queries with a crafted EDNS OPT record while EDNS Client Subnet is inserted. A remote attacker can send a crafted EDNS OPT record to bypass security rules.

The backend can receive EDNS options that were not filtered by DNSdist.


Affected software

dnsdist
Debian Linux
dnsdist (Debian package)

How to mitigate CVE-2026-42004

Install security update from vendor's website.

dnsdist - addressed in versions 1.9.15, 2.0.7
dnsdist (Debian package) - update to 1.9.15-0+deb13u1

External References

Related Security Bulletins