freenode
Security & Cryptography

PowerDNS patches high-severity DNS packet resource exhaustion bug

CVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.

PowerDNS has shipped updates for Authoritative Server, Recursor, and dnsdist to fix a high-severity flaw in which a crafted DNS packet can force elevated memory and CPU consumption.

Tracked as CVE-2026-52682 and described in Security Advisory 2026-11, the issue affects operators running any of the three products as public or internal DNS infrastructure. An attacker who can send queries may degrade service performance without needing authentication, raising the risk of denial-of-service under load.

Fixed releases are Authoritative Server 4.9.17, 5.0.7, and 5.1.4; Recursor 5.2.13, 5.3.10, and 5.4.5; and dnsdist 1.9.16, 2.0.8, and 2.1.1. Otto Moerbeek announced the packages on the oss-security list and pointed operators to the product changelogs and the full advisory for details.

PowerDNS also noted a recent change to its open-source end-of-life policy: older release trains now receive support for one year after the following major release.