CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains

Published Jul 20, 2026
·
Updated

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains.

Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to a potential Denial of Service.

The guard $link < $offset prevents forward and circular chains, but still allows arbitrarily long backward chains. The per-offset cache ($cache) is populated at the start of each call and short-circuits only re-traverses of the same offset - the initial descent through a fresh chain still recurses at full depth.

A crafted packet can chain two-byte compression pointers so that each one points two bytes earlier than the previous, producing a chain length of offset / 2. For the 14-bit pointer field (max offset 16383) this gives up to ~8191 recursive frames. For a TCP DNS message the limit is the 16-bit length field (~32767 frames). Perl's default C stack handles only a few thousand frames; beyond that the process receives SIGSEGV or similar, which is a denial-of-service for any application parsing untrusted DNS data.

The vulnerability is triggered by Net::DNS::Packet->new(\$wire) i.e. any point where the library decodes a DNS message from the network.

Affected Software

1 affected component
CPAN Net::DNS<=1.55

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Net::DNS (Perl) to a version that resolves this vulnerability.

    Fixed in 1.56
  2. Compensating control

    Apply the mitigation/guard against triggering the vulnerability by ensuring DNS messages are only parsed from trusted sources; the vulnerability is triggered when the library decodes a DNS message from the network (Net::DNS::Packet->new($wire)).

Event History

Jul 20, 2026
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-64194?

CVE-2026-64194 has a high severity rating of 7.5 based on the CVSS 3.1 metrics.

2

What does CVE-2026-64194 affect?

CVE-2026-64194 affects Net::DNS versions through 1.55 for Perl.

3

How does CVE-2026-64194 create a Denial of Service?

CVE-2026-64194 allows Denial of Service by exploiting deep DNS compression pointer chains, leading to stack saturation.

4

How do I fix CVE-2026-64194?

To fix CVE-2026-64194, upgrade to Net::DNS version 1.56 or later.

5

What is the nature of the vulnerability in CVE-2026-64194?

The nature of the vulnerability in CVE-2026-64194 is that it involves an unbounded recursion in the decoding of DNS compression pointers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203