PT-2026-71364 · Openstack · Openstack Designate
CVE-2026-71194
·
Published
2026-08-12
·
Updated
2026-08-13
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenStack Designate versions prior to 22.0.2
Description
The mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. If two zones with the same name exist across different pools, the lookup fails, leading the handler to return REFUSED for all DNS queries through that path. The
handle notify() function is exploitable via a single unauthenticated UDP packet. This issue affects legitimate same-tenant cross-pool configurations and is not mitigated by BIND9 views, as mDNS operates as a shared service upstream of view configurations.Recommendations
Update to version 22.0.2 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Designate