CVE-2026-64194

EUVD-2026-46052
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains.

Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to a potential Denial of Service.

The guard `$link < $offset` prevents forward and circular chains, but still allows arbitrarily long backward chains. The per-offset cache (`$cache`) is populated at the start of each call and short-circuits only re-traverses of the same offset - the initial descent through a fresh chain still recurses at full depth.

A crafted packet can chain two-byte compression pointers so that each one points two bytes earlier than the previous, producing a chain length of `offset / 2`. For the 14-bit pointer field (max offset 16383) this gives up to ~8191 recursive frames. For a TCP DNS message the limit is the 16-bit length field (~32767 frames). Perl's default C stack handles only a few thousand frames; beyond that the process receives SIGSEGV or similar, which is a denial-of-service for any application parsing untrusted DNS data.

The vulnerability is triggered by `Net::DNS::Packet->new(\$wire)` i.e. any point where the library decodes a DNS message from the network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.77%
Debian logo
Debian Releases
Debian Product
Codename
libnet-dns-perl
bookworm
vulnerable
bookworm (security)
1.36-1+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
1.29-1+deb11u1
fixed
forky
1.56-1
fixed
sid
1.56-1
fixed
trixie
vulnerable
trixie (security)
1.56-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libnet-dns-perl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-Net-DNS
Amazon Linux 2
0:0.72-6.amzn2.0.3
fixed
Amazon Linux 2023
0:1.56-1.amzn2023.0.1
fixed
perl-Net-DNS-Nameserver
Amazon Linux 2
0:0.72-6.amzn2.0.3
fixed
Amazon Linux 2023
0:1.56-1.amzn2023.0.1
fixed
perl-Net-DNS-debuginfo
Amazon Linux 2
0:0.72-6.amzn2.0.3
fixed
perl-Net-DNS-tests
Amazon Linux 2023
0:1.56-1.amzn2023.0.1
fixed