Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
Applications and libraries need to be ported to hickory-resolver v0.26 since v0.25 is no longer maintained. It appears that the only dependent application of rust-hickory-resolver0.25 is currently rust-sequoia-sq, and there is upstream work (not yet part of a tagged release) to port to hickory-dns v0.26. With the retirement of rust-sequoia-sq from EPEL 9 (due to it being moved to RHEL proper), there will no longer be any affected packages in EPEL.