Incorrect Control Flow Scoping in dnsdist - CVE-2026-40208
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect handling of invalid frames in the DoH3 query processing logic when processing DoH3 GET queries with an invalid DATA frame. A remote attacker can send crafted DoH3 GET queries with an invalid DATA frame to cause a denial of service.
The issue can delay the processing of DoH3 queries.
Affected software
Debian Linux
dnsdist (Debian package)
How to mitigate CVE-2026-40208
dnsdist (Debian package) - update to 1.9.15-0+deb13u1