CVE-2026-33601: Insufficient validation of zonemd record
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33601?
CVE-2026-33601 has been classified as a denial of service vulnerability due to a null pointer dereference.
How do I fix CVE-2026-33601?
To mitigate CVE-2026-33601, upgrade your PowerDNS recursor to a version that is not affected, specifically later than 5.2.9, 5.3.6, or 5.4.0.
What software is affected by CVE-2026-33601?
CVE-2026-33601 affects PowerDNS recursor versions from 5.2.0 to 5.2.9, 5.3.0 to 5.3.6, and specifically 5.4.0.
Can CVE-2026-33601 be exploited remotely?
Yes, CVE-2026-33601 can be exploited remotely if a malicious authoritative server is used.
What impact does CVE-2026-33601 have on my system?
Exploitation of CVE-2026-33601 can lead to a denial of service, making the affected PowerDNS recursor unavailable.