Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade knot | Jul 30, 2024 | Feb 9, 2017 |
| Freebsd | — | Upgrade bind9-develUpgrade knot2Upgrade bind99Upgrade knotUpgrade powerdnsUpgrade bind910Upgrade nsdUpgrade bind911Upgrade knot1 | Dec 10, 2025 | Aug 10, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 9, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub