PT-2026-64452 · Unknown · Knot Resolver

CVE-2026-66374

·

Published

2026-07-25

·

Updated

2026-07-27

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Knot Resolver versions prior to 6.4.1
Description A heap-based buffer overflow exists in the DoQ (DNS-over-QUIC) receive path, which could allow remote code execution. A heap-based buffer overflow occurs when a program writes more data to a heap-allocated memory block than it can hold, potentially corrupting memory and allowing an attacker to execute arbitrary code.
Recommendations Update Knot Resolver to version 6.4.1 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66374

Affected Products

Knot Resolver