Reachable Assertion in dnsdist - CVE-2024-25581
Published: May 13, 2024
dnsdist
PowerDNS.COM B.V.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or
DNS over TLS backend. A remote attacker can send a specially crafted request for a zone transfer
(AXFR or IXFR) over DNS over HTTPS and perform a denial of service (DoS) attack.