CVE-2026-66374: Buffer Overflow
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Knot Resolverto a version that resolves this vulnerability.Fixed in 6.4.1 - Compensating control
Limit network access to Knot Resolver’s DoQ (DNS-over-QUIC) service from untrusted clients until the upgrade to 6.4.1 is completed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66374?
The severity of CVE-2026-66374 is classified as high with a score of 8.1.
How do I fix CVE-2026-66374?
To fix CVE-2026-66374, upgrade to Knot Resolver version 6.4.1 or later.
What type of vulnerability is CVE-2026-66374?
CVE-2026-66374 is a buffer overflow vulnerability that allows for remote code execution.
What software is affected by CVE-2026-66374?
Knot Resolver versions prior to 6.4.1 are affected by CVE-2026-66374.
What is the attack vector for CVE-2026-66374?
The attack vector for CVE-2026-66374 involves the DoQ (DNS-over-QUIC) receive path.