An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service.

The remedy is: upgrade to the patched 5.2.1 version.

We would like to thank Volodymyr Ilyin for bringing this issue to our attention.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-10022 An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing this issue to our attention.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 07 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
References

Mon, 07 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Apr 2025 13:45:00 +0000

Type Values Removed Values Added
Description An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing this issue to our attention.
Title A crafted zone can lead to an illegal memory access in the PowerDNS Recursor
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2025-04-07T16:03:15.727Z

Reserved: 2025-03-18T08:39:46.884Z

Link: CVE-2025-30195

cve-icon Vulnrichment

Updated: 2025-04-07T16:03:15.727Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-07T14:15:24.813

Modified: 2025-04-07T16:15:25.850

Link: CVE-2025-30195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:06Z