CVE-2026-10846: Insufficient verification that responses belong to a query
Insufficient verification that responses belong to a query
Other sources
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ldnsto a version that resolves this vulnerability.Fixed in 1.9.2-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.3-3 - Upgrade
Upgrade
NLnet Labs ldnsto a version that resolves this vulnerability.Fixed in 1.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10846?
The severity of CVE-2026-10846 is rated high with a CVSS score of 8.2.
What issue does CVE-2026-10846 describe?
CVE-2026-10846 describes insufficient verification that responses belong to a query in NLnet Labs ldns when used as a resolver over UDP.
How do I fix CVE-2026-10846?
To fix CVE-2026-10846, update to NLnet Labs ldns version 1.9.1 or later.
Which versions of NLnet Labs ldns are affected by CVE-2026-10846?
NLnet Labs ldns versions from 1.2.0 up to and including 1.9.0 are affected by CVE-2026-10846.
What are the impacted software components for CVE-2026-10846?
The impacted software components for CVE-2026-10846 are NLnet Labs ldns and NLnet Labs drill.