logo

Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw

ID: eb2c5839-4804-5db4-810d-8e398ded4329

STIX ID: report--eb2c5839-4804-5db4-810d-8e398ded4329

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Do Son

...
...

Knot Resolver contains a size-tracking heap out-of-bounds bug in its DNS-over-QUIC listener (kresd) that allows unauthenticated remote code execution; a public PoC exists, CZ.NIC patched the issue in 6.4.1, and the flaw is tracked as CVE-2026-66374 (CVSS 8.1).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.