Bug 2506361 (CVE-2026-52684) - CVE-2026-52684 pdns-recursor: prefetch feature allows persistent ghost domain cache poisoning attack
Summary: CVE-2026-52684 pdns-recursor: prefetch feature allows persistent ghost domain...
Keywords:
Status: NEW
Alias: CVE-2026-52684
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2506753 2506754
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-23 09:01 UTC by OSIDB Bzimport
Modified: 2026-07-24 14:58 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-23 09:01:25 UTC
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the 
child records are used immediately if not expired and thus valid, or the
 records are expired, and in that case not used.  So this case 
can only happen if almost expired records are used to refresh the 
authoritative NS records.


Note You need to log in before you can comment on or make changes to this bug.