Resource management error in PowerDNS Recursor - CVE-2024-25590
Published: October 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application. A remote attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.
Affected software
Debian Linux
Fedora
pdns-recursor (Debian package)
pdns-recursor
How to mitigate CVE-2024-25590
pdns-recursor (Debian package) - update to 4.8.8-1+deb12u1
pdns-recursor - addressed in versions 4.9.9-1.fc39, 5.0.9-1.fc40, 5.1.2-1.fc41