Impact
The vulnerability involves insufficient validation of DNS response headers received from authoritative servers, which can cause the Recursor to reject queries or become unresponsive. Based on the description, it is inferred that a malformed header can lead to a denial of service for clients relying on the Recursor.
Affected Systems
The affected product is PowerDNS Recursor, 5.4.x branch. Users running this branch are potentially impacted; no other product lines are noted in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation to date. EPSS is not available for this entry. An attacker who can control or manipulate an authoritative DNS server would need to craft responses with invalid header values that bypass the existing validation logic. The fix adds extra validation of incoming answers, mitigating this attack pattern. The threat remains confined to denial of service or incorrect query handling rather than full system compromise.
OpenCVE Enrichment