CVE-2023-26249: High severity go-resolver vulnerability
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26249?
CVE-2023-26249 is a vulnerability in Knot Resolver before version 5.6.0 that allows attackers to consume its resources, launch amplification attacks, and potentially cause a denial of service.
How does CVE-2023-26249 affect Knot Resolver?
CVE-2023-26249 affects Knot Resolver before version 5.6.0 by allowing a single client query to lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.
What is the severity of CVE-2023-26249?
CVE-2023-26249 has a severity rating of high, with a score of 7.5.
How can I fix the CVE-2023-26249 vulnerability?
To fix the CVE-2023-26249 vulnerability, you should update Knot Resolver to version 5.6.0 or newer.
Where can I find more information about CVE-2023-26249?
You can find more information about CVE-2023-26249 at the following link: [https://www.knot-resolver.cz/2023-01-26-knot-resolver-5.6.0.html](https://www.knot-resolver.cz/2023-01-26-knot-resolver-5.6.0.html).