PT-2026-64166 · Debian+1 · Knot
CVE-2026-39155
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Knot DNS versions prior to 3.4.10
Knot DNS versions 3.5.x prior to 3.5.4
Description
A flaw exists in the
mod-onlinesign module where the next NSEC owner name is computed incorrectly. This error creates an overly broad authenticated denial interval, which enables downstream validating resolvers that utilize aggressive negative caching to synthesize negative responses for legitimate names, resulting in a resolver-side denial of service.Recommendations
Update Knot DNS to version 3.4.10 or later.
Update Knot DNS to version 3.5.4 or later.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knot