NIXPKGS-2026-0012
published on 13 Jan 2026
Permalink
CVE-2025-59030
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
Affected products
pdns-recursor
- <5.1.9
- <5.3.3
- <5.2.7
Matching in nixpkgs
pkgs.pdns-recursor
Recursive DNS server
Package maintainers
-
@rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org>