PT-2026-48381 · Nlnet+4 · Ldns+5

·

CVE-2026-10846

·

Published

2026-06-09

·

Updated

2026-08-04

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NLnet Labs ldns versions 1.2.0 through 1.9.0
Description When used in applications as a stub resolver over UDP, the software fails to match the query destination address and port with the response source address and port. Additionally, it does not verify that the query ID or the query question matches the response. This deficiency allows for off-path poisoning attacks, where an attacker sends forged responses to the resolver. The drill tool included with the software is also affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:49520
ALSA-2026:49836
ALSA-2026:50108
AZL-89715
BDU:2026-12817
CVE-2026-10846
OESA-2026-2788
OPENSUSE-SU-2026:10998-1
OPENSUSE-SU-2026:21093-1
RHSA-2026:49520
RHSA-2026:49836
RHSA-2026:50108
RHSA-2026:53402
RHSA-2026:54244
RHSA-2026:54254
RHSA-2026:54377
SUSE-SU-2026:22167-1
SUSE-SU-2026:2461-1
SUSE-SU-2026:2462-1
USN-8449-1

Affected Products

Freebsd
Linuxmint
Rocky Linux
Ubuntu
Drill
Ldns