Bug 2506754 - CVE-2026-52684 pdns-recursor: prefetch feature allows persistent ghost domain cache poisoning attack [epel-all]
Summary: CVE-2026-52684 pdns-recursor: prefetch feature allows persistent ghost domain...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: pdns-recursor
Version: epel10
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Filipe Rosset
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["b6dc092c-08a0-46f8-ba09-f...
Depends On:
Blocks: CVE-2026-52684
TreeView+ depends on / blocked
 
Reported: 2026-07-24 14:58 UTC by Guilherme de Almeida Suckevicz
Modified: 2026-07-24 14:58 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2026-07-24 14:58:58 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the 
child records are used immediately if not expired and thus valid, or the
 records are expired, and in that case not used.  So this case 
can only happen if almost expired records are used to refresh the 
authoritative NS records.


Note You need to log in before you can comment on or make changes to this bug.