{"id":3625,"date":"2025-04-30T10:00:58","date_gmt":"2025-04-30T10:00:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/30\/powerdns-dnsdist-vulnerability-let-attackers-cause-denial-of-service-condition\/"},"modified":"2025-04-30T10:00:58","modified_gmt":"2025-04-30T10:00:58","slug":"powerdns-dnsdist-vulnerability-let-attackers-cause-denial-of-service-condition","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/30\/powerdns-dnsdist-vulnerability-let-attackers-cause-denial-of-service-condition\/","title":{"rendered":"PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition"},"content":{"rendered":"<p>    PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A high-severity vulnerability (CVE-2025-30194) in <a href=\"https:\/\/cybersecuritynews.com\/powerdns-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerDNS<\/a> DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to trigger denial-of-service (DoS) conditions by exploiting flaws in its DNS-over-HTTPS (DoH) implementation.\u00a0<\/p>\n<p>The vulnerability, disclosed in PowerDNS Security Advisory, affects DNSdist versions 1.9.0 through 1.9.8 when configured to use the nghttp2 library for DoH processing.<\/p>\n<p>Successful exploitation crashes the DNSdist service via a double-free memory corruption event, disrupting DNS resolution for dependent systems.<\/p>\n<h2 class=\"wp-block-heading\"><strong>High-Severity DoS in DNSdist via nghttp2 DoH<\/strong><\/h2>\n<p>The vulnerability stems from improper memory management when handling maliciously crafted DoH exchanges.\u00a0<\/p>\n<p>Attackers exploiting this flaw send specially structured HTTP\/2 requests that cause DNSdist to attempt freeing the same memory region twice-a critical error classified as CWE-416 (Use After Free).\u00a0<\/p>\n<p>This triggers a segmentation fault, terminating the DNSdist process entirely. The attack requires no <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> and can be executed remotely over the network, earning it a CVSS v3.1 score of 7.5.<\/p>\n<p>Notably, the issue only manifests in configurations using the nghttp2 provider for incoming DoH traffic, a default setting since DNSdist 1.9.0.\u00a0<\/p>\n<p>Systems relying on the legacy h2o library or earlier DNSdist versions remain unaffected.\u00a0<\/p>\n<p>PowerDNS engineers traced the root cause to an edge-case interaction between nghttp2\u2019s request handling and DNSdist\u2019s internal resource management logic, exacerbated by certain HTTP\/2 frame sequences.<\/p>\n<p>With DNSdist deployed in critical infrastructure roles-including recursive resolver farms, authoritative <a href=\"https:\/\/cybersecuritynews.com\/ingressnightmare\/\" target=\"_blank\" rel=\"noreferrer noopener\">DNS clusters<\/a>, and DDoS-protected networks-this vulnerability poses significant operational risks.\u00a0<\/p>\n<p>An unpatched instance could suffer prolonged outages, as restarting the crashed service provides only temporary relief until the next attack<\/p>\n<p>The discovery of this vulnerability is credited to Charles Howes, who brought the issue to the attention of PowerDNS.\u00a0<\/p>\n<p>The swift <a href=\"https:\/\/www.dnsdist.org\/security-advisories\/powerdns-advisory-for-dnsdist-2025-02.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">response from<\/a> PowerDNS in releasing a fixed version demonstrates the importance of community involvement in maintaining the security of critical infrastructure software.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>PowerDNS DNSdist versions 1.9.0 to 1.9.8 (fixed in 1.9.9)<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Denial of service (DoS)<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>DNSdist must be configured to provide DoH using the nghttp2 provider\u00a0<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>7.5 (High)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Workaround<\/strong><\/h2>\n<p>To mitigate this vulnerability, users are <a href=\"https:\/\/www.dnsdist.org\/security-advisories\/powerdns-advisory-for-dnsdist-2025-02.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advised<\/a> to upgrade to the patched version 1.9.9 of DNSdist.\u00a0<\/p>\n<p>For those unable to upgrade immediately, a temporary workaround is to switch to the h2o provider until the update can be implemented.\u00a0<\/p>\n<p>This ensures that DoH services remain operational while preventing exploitation of the vulnerability. The PowerDNS DNSdist vulnerability highlights the importance of keeping software up to date, especially for critical infrastructure components like DNS services.\u00a0<\/p>\n<p>As the use of DoH continues to grow, ensuring the security of these services is paramount to prevent disruptions and maintain network integrity.\u00a0<\/p>\n<p>Users are encouraged to apply the patch or implement the workaround to protect against potential attacks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Are you from the SOC and DFIR Teams? \u2013 Analyse Malware Incidents &amp; get live Access with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn_apr&amp;utm_medium=article&amp;utm_campaign=how-script-based-malware-attacks-work&amp;utm_content=demo&amp;utm_term=230425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/powerdns-dnsdist-vulnerability\/\">PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/powerdns-dnsdist-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition A high-severity vulnerability (CVE-2025-30194) in PowerDNS DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to trigger denial-of-service (DoS) conditions by exploiting flaws in its DNS-over-HTTPS (DoH) implementation.\u00a0 The vulnerability, disclosed in PowerDNS Security Advisory, affects DNSdist versions 1.9.0 through 1.9.8 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1198,131],"tags":[130],"class_list":["post-3625","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-dos","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3625"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3625"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3625\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}