Bug 2542978 - CVE-2026-93657 rust-hickory-resolver0.25: hickory-resolver: DNSSEC validation bypass allows forged DNS records [epel-all]
Summary: CVE-2026-93657 rust-hickory-resolver0.25: hickory-resolver: DNSSEC validation...
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: rust-hickory-resolver0.25
Version: epel10
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Rust SIG
QA Contact:
URL:
Whiteboard: {"flaws": ["6a2d8040-7455-49ab-8227-c...
Depends On:
Blocks: CVE-2026-93657
TreeView+ depends on / blocked
 
Reported: 2026-09-29 06:59 UTC by Ganesh
Modified: 2026-09-29 15:03 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-09-29 06:59:43 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.

Comment 1 Fabio Valentini 2026-09-29 15:03:10 UTC
Applications and libraries need to be ported to hickory-resolver v0.26 since v0.25 is no longer maintained.

It appears that the only dependent application of rust-hickory-resolver0.25 is currently rust-sequoia-sq, and there is upstream work (not yet part of a tagged release) to port to hickory-dns v0.26.

With the retirement of rust-sequoia-sq from EPEL 9 (due to it being moved to RHEL proper), there will no longer be any affected packages in EPEL.


Note You need to log in before you can comment on or make changes to this bug.