Out-of-Bounds Write Vulnerability in DNSdist by PowerDNS
CVE-2026-27853

5.9MEDIUM

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-27853?

A flaw in DNSdist allows an attacker to exploit an out-of-bounds write condition by sending specially crafted DNS responses. This can occur through the DNSQuestion:changeName or DNSResponse:changeName Lua methods. The manipulation can lead to packets exceeding the maximum allowed size of 65535 bytes, resulting in the potential crashing of the service and causing denial of service. Administrators are advised to review their DNSdist configurations and apply recommended updates to mitigate this risk.

Affected Version(s)

DNSdist 1.9.0 < 1.9.12

DNSdist 2.0.0 < 2.0.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ilya rozentsvaig
.