PowerDNS Fixes Flaws Granting Server Crashes and Memory Corruption
ID: bba19285-9412-5da3-a6d4-9b679f989b66
STIX ID: report--bba19285-9412-5da3-a6d4-9b679f989b66
Feed Name: securityonline.info
PowerDNS has released advisories for multiple vulnerabilities in its Authoritative Server that can cause Denial of Service, memory corruption, and an information disclosure issue in older branches. The most serious is CVE-2026-42001 (High) allowing a crash when autosecondary servers receive malformed SOA responses; other CVEs affect GSS-TSIG concurrency, AXFR name escaping, catalog zone quoting, and PROXY protocol view selection. Administrators are advised to upgrade to 4.9.15 or 5.0.5 or temporarily disable the affected features (GSS-TSIG, autosecondary, views) to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
