CVE-2026-42002: Concurrency and locking defects in GSS-TSIG
Published May 21, 2026
·Updated
Concurrency and locking defects in GSS-TSIG
Affected Software
2 affected components
PowerDNS Authoritative>=4.7.0<4.9.15
PowerDNS Authoritative>=5.0.0<5.0.5
Event History
May 21, 2026
CVE Published
via MITRE·09:27 AM
Data Sourced
via MITRE·09:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-42002?
The severity of CVE-2026-42002 is high, rated at 7.5.
2
How does CVE-2026-42002 affect PowerDNS Authoritative?
CVE-2026-42002 presents concurrency and locking defects within the GSS-TSIG implementation of PowerDNS Authoritative.
3
What is the risk associated with CVE-2026-42002?
CVE-2026-42002 has a risk rating of 45, indicating significant potential impact.
4
What type of vulnerability is CVE-2026-42002 classified as?
CVE-2026-42002 is classified as a race condition vulnerability.
5
How can I remediate the vulnerability identified as CVE-2026-42002?
To remediate CVE-2026-42002, it is recommended to update to the latest version of PowerDNS Authoritative that addresses this issue.