PT-2026-64452 · Unknown · Knot Resolver
CVE-2026-66374
·
Published
2026-07-25
·
Updated
2026-07-27
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Knot Resolver versions prior to 6.4.1
Description
A heap-based buffer overflow exists in the DoQ (DNS-over-QUIC) receive path, which could allow remote code execution. A heap-based buffer overflow occurs when a program writes more data to a heap-allocated memory block than it can hold, potentially corrupting memory and allowing an attacker to execute arbitrary code.
Recommendations
Update Knot Resolver to version 6.4.1 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knot Resolver