Reachable Assertion in dnsdist - CVE-2024-25581
Published: May 13, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or
DNS over TLS backend. A remote attacker can send a specially crafted request for a zone transfer
(AXFR or IXFR) over DNS over HTTPS and perform a denial of service (DoS) attack.
Affected software
Fedora
dnsdist
How to mitigate CVE-2024-25581
dnsdist - addressed in versions 1.9.7-1.fc39, 1.9.7-1.fc40, 1.9.7-1.fc41