Impact
Knot DNS versions before 3.4.10 and before 3.5.4 contain a flaw in the mod‑onlinesign module that incorrectly computes the next NSEC owner name. The incorrect calculation creates an overly broad authenticated denial interval, which downstream resolvers that use aggressive negative caching may treat as a valid negative response. When such a resolver receives a query for a legitimate name, it can be tricked into returning a negative answer, effectively denying legitimate resolution requests and causing a denial‑of‑service condition on the resolver side.
Affected Systems
Knot DNS 3.4.9 and earlier, as well as Knot DNS 3.5.3 and earlier. The vulnerability is present in all releases prior to 3.4.10 and 3.5.4, respectively.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a moderate severity vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Exploit requires a modifiable query path to a vulnerable Knot DNS server and the presence of a downstream resolver that relies heavily on negative caching. The attack is therefore feasible in environments where resolvers aggressively cache negative responses, but overall risk remains moderate and the window of attack is limited.
OpenCVE Enrichment