Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: pdns-recursor

Found 10 matching suggestions

Published
updated 2 days, 2 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package rotp
  • @LeSuisse removed
    2 maintainers
    • @rnhmjoj
    • @jtrees
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Crafted delegations or IP fragments can poison cached delegations in Recursor

Crafted delegations or IP fragments can poison cached delegations in Recursor.

Affected products

pdns-recursor
  • <5.2.6
  • <5.1.8
  • <5.3.1

Matching in nixpkgs

Ignored packages (1)

pkgs.rotp

Open-source modernization of the 1993 classic "Master of Orion", written in Java

Package maintainers

Ignored maintainers (2)
Fixed in:
* https://github.com/NixOS/nixpkgs/commit/42bb4a06d4a01d3dbfca9a19a9daef7cb7560374 (25.11)
* https://github.com/NixOS/nixpkgs/commit/f4cf3fc15536fdc273350b98ad8f4289f32512d2 (unstable)
Published
updated 2 days, 3 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package rotp
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

Affected products

pdns-recursor
  • <5.1.10
  • <5.3.5
  • <5.2.8

Matching in nixpkgs

Ignored packages (1)

pkgs.rotp

Open-source modernization of the 1993 classic "Master of Orion", written in Java

Package maintainers

Upstream advisory: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-01.html
Untriaged
updated 2 days, 2 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package rotp
Crafted delegations or IP fragments can poison cached delegations in Recursor

Crafted delegations or IP fragments can poison cached delegations in Recursor.

Affected products

pdns-recursor
  • <5.2.6
  • <5.1.8
  • <5.3.1

Matching in nixpkgs

Ignored packages (1)

pkgs.rotp

Open-source modernization of the 1993 classic "Master of Orion", written in Java

Package maintainers

Untriaged
updated 1 day, 3 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package rotp
Crafted zones can lead to increased incoming network traffic

Crafted zones can lead to increased incoming network traffic.

Affected products

pdns-recursor
  • <5.1.10
  • <5.3.5
  • <5.2.8

Matching in nixpkgs

Ignored packages (1)

pkgs.rotp

Open-source modernization of the 1993 classic "Master of Orion", written in Java

Package maintainers

Published
updated 4 weeks, 1 day ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

Affected products

pdns-recursor
  • <5.1.9
  • <5.2.7
  • <5.3.3

Matching in nixpkgs

Package maintainers

Upstream advisory: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-08.html
Dismissed
updated 4 weeks, 1 day ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed
Internal logic flaw in cache management can lead to a denial of service in PowerDNS Recursor

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

Affected products

pdns-recursor
  • <5.3.2

Matching in nixpkgs

Package maintainers

Upstream advisory: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-07.html

5.2.x branch is not impacted.
Untriaged
created 4 months, 3 weeks ago
A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers. The most strict mitigation done when the new setting outgoing.edns_subnet_harden (old style name edns-subnet-harden) is enabled.

Affected products

pdns-recursor
  • ==5.1.6
  • ==5.0.12
  • ==5.2.4

Matching in nixpkgs

Package maintainers

Untriaged
created 4 months, 3 weeks ago
A crafted zone can lead to an illegal memory access in the PowerDNS Recursor

An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing this issue to our attention.

Affected products

pdns-recursor
  • ==5.2.0

Matching in nixpkgs

Package maintainers

Untriaged
created 4 months, 3 weeks ago
Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.

Affected products

pdns-recursor
  • <5.1.2
  • <4.9.9
  • <5.0.9

Matching in nixpkgs

Package maintainers

Untriaged
created 4 months, 3 weeks ago
Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

Affected products

powerdns
  • ==4.9.4
  • ==5.0.3
  • ==4.8.7
pdns-recursor
  • ==4.9.4
  • ==5.0.3
  • ==4.8.7

Matching in nixpkgs

Package maintainers