When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to a Denial of Service. DNS over HTTPS is not enabled by default, and backends are using plain DNS (Do53) by default.
{
"cwe_ids": [
"CWE-20"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25581.json",
"cna_assigner": "OX"
}{
"extracted_events": [
{
"introduced": "1.9.0"
},
{
"last_affected": "1.9.0"
},
{
"introduced": "1.9.1"
},
{
"last_affected": "1.9.1"
},
{
"introduced": "1.9.2"
},
{
"last_affected": "1.9.2"
},
{
"introduced": "1.9.3"
},
{
"last_affected": "1.9.3"
}
],
"source": "AFFECTED_FIELD"
}