An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pdns-recursor | Dec 21, 2018 | Nov 9, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 9, 2018 |
| Debian | — | Upgrade pdns-recursor | Jul 30, 2024 | Nov 9, 2018 |
| Freebsd | — | Upgrade powerdns-recursorUpgrade powerdns-recursor40 | Nov 18, 2018 | Nov 17, 2018 |
| Suse | — | Upgrade pdns-recursor | Dec 18, 2018 | Nov 9, 2018 |
| Ubuntu | — | Upgrade pdns-recursor (Ubuntu Pro)Upgrade pdns-tools (Ubuntu Pro)Upgrade pdns-server (Ubuntu Pro) | Jan 15, 2025 | Nov 9, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub