CVE-2026-10846

EUVD-2026-35991
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.25%
Affected Products (NVD)
VendorProductVersion
nlnetlabsldns
1.2.0 ≤
𝑥
< 1.9.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ldns
bookworm
postponed
bullseye
postponed
forky
1.9.2-1
fixed
sid
1.9.2-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ldns
bionic
Fixed 1.7.0-3ubuntu4.1+esm1
released
focal
Fixed 1.7.0-4.1ubuntu1+esm2
released
jammy
Fixed 1.7.1-2ubuntu4+esm2
released
noble
Fixed 1.8.3-2ubuntu0.1~esm1
released
questing
ignored
resolute
Fixed 1.8.4-2ubuntu0.26.04.1~esm1
released
xenial
Fixed 1.6.17-8ubuntu0.1+esm2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
ldns-devel
suse enterprise desktop 15 SP7
1.8.3-150600.3.3.1
fixed
suse enterprise sap 15 SP4
1.7.0-150000.4.11.1
fixed
suse enterprise sap 15 SP5
1.7.0-150000.4.11.1
fixed
suse enterprise sap 15 SP6
1.8.3-150600.3.3.1
fixed
suse enterprise sap 15 SP7
1.8.3-150600.3.3.1
fixed
suse enterprise server 15 SP4
1.7.0-150000.4.11.1
fixed
suse enterprise server 15 SP5
1.7.0-150000.4.11.1
fixed
suse enterprise server 15 SP6
1.8.3-150600.3.3.1
fixed
suse enterprise server 15 SP7
1.8.3-150600.3.3.1
fixed
libldns2
suse enterprise sap 15 SP4
1.7.0-150000.4.11.1
fixed
suse enterprise sap 15 SP5
1.7.0-150000.4.11.1
fixed
suse enterprise server 15 SP4
1.7.0-150000.4.11.1
fixed
suse enterprise server 15 SP5
1.7.0-150000.4.11.1
fixed
libldns3
suse enterprise desktop 15 SP7
1.8.3-150600.3.3.1
fixed
suse enterprise sap 15 SP6
1.8.3-150600.3.3.1
fixed
suse enterprise sap 15 SP7
1.8.3-150600.3.3.1
fixed
suse enterprise server 15 SP6
1.8.3-150600.3.3.1
fixed
suse enterprise server 15 SP7
1.8.3-150600.3.3.1
fixed
perl-DNS-LDNS
suse enterprise sap 15 SP4
1.7.0-150000.4.11.1
fixed
suse enterprise sap 15 SP5
1.7.0-150000.4.11.1
fixed
suse enterprise sap 15 SP6
1.8.3-150600.3.3.1
fixed
suse enterprise server 15 SP4
1.7.0-150000.4.11.1
fixed
suse enterprise server 15 SP5
1.7.0-150000.4.11.1
fixed
suse enterprise server 15 SP6
1.8.3-150600.3.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ldns
RHEL 8
0:1.7.0-23.el8_10
fixed
RHEL 9
0:1.7.1-12.el9_8.1
fixed
ldns-devel
RHEL 8
0:1.7.0-23.el8_10
fixed
RHEL 9
0:1.7.1-12.el9_8.1
fixed
ldns-doc
RHEL 8
0:1.7.0-23.el8_10
fixed
RHEL 9
0:1.7.1-12.el9_8.1
fixed
ldns-utils
RHEL 8
0:1.7.0-23.el8_10
fixed
RHEL 9
0:1.7.1-12.el9_8.1
fixed
perl-ldns
RHEL 8
0:1.7.0-23.el8_10
fixed
RHEL 9
0:1.7.1-12.el9_8.1
fixed
python3-ldns
RHEL 8
0:1.7.0-23.el8_10
fixed
RHEL 9
0:1.7.1-12.el9_8.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
ldns
Azure Linux 3.0
0:1.8.3-3.azl3
fixed