Bug 2542976 - CVE-2026-93657 rust-hickory-resolver0.24: hickory-resolver: DNSSEC validation bypass allows forged DNS records [fedora-all]
Summary: CVE-2026-93657 rust-hickory-resolver0.24: hickory-resolver: DNSSEC validation...
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: rust-hickory-resolver0.24
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Rust SIG
QA Contact:
URL:
Whiteboard: {"flaws": ["6a2d8040-7455-49ab-8227-c...
Depends On:
Blocks: CVE-2026-93657
TreeView+ depends on / blocked
 
Reported: 2026-09-29 06:59 UTC by Ganesh
Modified: 2026-09-29 15:05 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-09-29 06:59:35 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.

Comment 1 Ben Beasley 2026-09-29 09:27:29 UTC
https://www.cve.org/CVERecord?id=CVE-2026-93657

https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6

It may be possible to backport the specific linked fix https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238 to 0.24, but it’s not quite trivial, and blindly patching security-critical code has its own risks. I’m not inclined to try to “fix” this within the rust-hickory-resolver0.24 compat package. Instead, the proper solution will be to find a way to migrate dependencies forward to hickory-dns 0.26, https://forge.fedoraproject.org/rust/backlog/issues/33, and retire the 0.24 and 0.25 compat packages.

Comment 2 Fabio Valentini 2026-09-29 15:05:43 UTC
Affected applications:

- rust-sequoia-chameleon-gnupg
- rust-sequoia-git
- rust-sequoia-octopus-librnp
- rust-sequoia-sq

There is upstream work (not yet part of a tagged release) to port sequoia-net and other sequoia-pgp crates to hickory-dns v0.26, which will resolve this issue.


Note You need to log in before you can comment on or make changes to this bug.