Bug 2542973 - CVE-2026-93657 trunk: hickory-resolver: DNSSEC validation bypass allows forged DNS records [fedora-all]
Summary: CVE-2026-93657 trunk: hickory-resolver: DNSSEC validation bypass allows forge...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: trunk
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Jens Reimann
QA Contact:
URL:
Whiteboard: {"flaws": ["6a2d8040-7455-49ab-8227-c...
Depends On:
Blocks: CVE-2026-93657
TreeView+ depends on / blocked
 
Reported: 2026-09-29 06:59 UTC by Ganesh
Modified: 2026-09-29 06:59 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-09-29 06:59:15 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.


Note You need to log in before you can comment on or make changes to this bug.