Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 953379 (CVE-2025-30195) - =net-dns/pdns-recursor-5.2.0: crafted zone can lead to denial of service
Summary: =net-dns/pdns-recursor-5.2.0: crafted zone can lead to denial of service
Status: RESOLVED FIXED
Alias: CVE-2025-30195
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://docs.powerdns.com/recursor/se...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2025-04-07 18:53 UTC by Sven Wegener
Modified: 2025-04-09 09:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sven Wegener gentoo-dev 2025-04-07 18:53:30 UTC
From $URL:

CVE: CVE-2025-30195
Date: 7th of April 2025.
Affects: PowerDNS Recursor 5.2.0
Not affected: PowerDNS Recursor 5.2.1 and versions before 5.2.0
Severity: High
Impact: Denial of service
Exploit: This problem can be triggered by an attacker publishing a crafted zone
Risk of system compromise: None
Solution: Upgrade to patched version
An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service.

CVSS Score: 7.5, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&version=3.1

The remedy is: upgrade to the patched 5.2.1 version.

We would like to thank Volodymyr Ilyin for bringing this issue to our attention.
Comment 1 Larry the Git Cow gentoo-dev 2025-04-07 19:14:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7bada93b3742a9d08a1c77a2277c213f45b56b1d

commit 7bada93b3742a9d08a1c77a2277c213f45b56b1d
Author:     Sven Wegener <swegener@gentoo.org>
AuthorDate: 2025-04-07 18:54:08 +0000
Commit:     Sven Wegener <swegener@gentoo.org>
CommitDate: 2025-04-07 19:14:10 +0000

    net-dns/pdns-recursor: add 5.2.1, drop 5.2.0
    
    Closes: https://bugs.gentoo.org/948134
    Bug: https://bugs.gentoo.org/953379
    Signed-off-by: Sven Wegener <swegener@gentoo.org>

 net-dns/pdns-recursor/Manifest                                       | 2 +-
 .../{pdns-recursor-5.2.0.ebuild => pdns-recursor-5.2.1.ebuild}       | 5 +++++
 2 files changed, 6 insertions(+), 1 deletion(-)
Comment 2 Sven Wegener gentoo-dev 2025-04-07 19:18:17 UTC
5.2.0 was the only vulnerable version and was never marked stable.
Comment 3 Hans de Graaff gentoo-dev Security 2025-04-09 09:11:10 UTC
(In reply to Sven Wegener from comment #2)
> 5.2.0 was the only vulnerable version and was never marked stable.

Based on this I’ve set the whiteboard to ~3.