logo

PowerDNS Fixes Flaws Granting Server Crashes and Memory Corruption

ID: bba19285-9412-5da3-a6d4-9b679f989b66

STIX ID: report--bba19285-9412-5da3-a6d4-9b679f989b66

Feed Name: securityonline.info

Threat Score
50/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

PowerDNS has released advisories for multiple vulnerabilities in its Authoritative Server that can cause Denial of Service, memory corruption, and an information disclosure issue in older branches. The most serious is CVE-2026-42001 (High) allowing a crash when autosecondary servers receive malformed SOA responses; other CVEs affect GSS-TSIG concurrency, AXFR name escaping, catalog zone quoting, and PROXY protocol view selection. Administrators are advised to upgrade to 4.9.15 or 5.0.5 or temporarily disable the affected features (GSS-TSIG, autosecondary, views) to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.