CVE-2026-64193

EUVD-2026-46051
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR.

Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.
Eval Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 53.72%
Debian logo
Debian Releases
Debian Product
Codename
libnet-dns-perl
bookworm
1.36-1
fixed
bookworm (security)
1.36-1+deb12u1
fixed
bullseye
1.29-1
fixed
bullseye (security)
1.29-1+deb11u1
fixed
forky
1.56-1
fixed
sid
1.56-1
fixed
trixie
vulnerable
trixie (security)
1.56-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libnet-dns-perl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-Net-DNS
Amazon Linux 2023
0:1.56-1.amzn2023.0.1
fixed
perl-Net-DNS-Nameserver
Amazon Linux 2023
0:1.56-1.amzn2023.0.1
fixed
perl-Net-DNS-tests
Amazon Linux 2023
0:1.56-1.amzn2023.0.1
fixed