Description

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.

INFO

Published Date :

2026-03-31T11:57:26.914Z

Last Modified :

2026-03-31T13:18:41.769Z

Source :

OX
AFFECTED PRODUCTS

The following products are affected by CVE-2026-24028 vulnerability.

Vendors Products
Powerdns
  • Dnsdist
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-24028.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact