CVE-2026-27854
EUVD-2026-1740931.03.2026, 12:16
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-free and potentially a crash resulting in denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| powerdns | dnsdist | 1.9.0 ≤ 𝑥 < 1.9.12 |
| powerdns | dnsdist | 2.0.0 ≤ 𝑥 < 2.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration