Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
https://www.cve.org/CVERecord?id=CVE-2026-93657 https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6 It may be possible to backport the specific linked fix https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238 to 0.24, but it’s not quite trivial, and blindly patching security-critical code has its own risks. I’m not inclined to try to “fix” this within the rust-hickory-resolver0.24 compat package. Instead, the proper solution will be to find a way to migrate dependencies forward to hickory-dns 0.26, https://forge.fedoraproject.org/rust/backlog/issues/33, and retire the 0.24 and 0.25 compat packages.
Affected applications: - rust-sequoia-chameleon-gnupg - rust-sequoia-git - rust-sequoia-octopus-librnp - rust-sequoia-sq There is upstream work (not yet part of a tagged release) to port sequoia-net and other sequoia-pgp crates to hickory-dns v0.26, which will resolve this issue.