CVE-2025-30192

Source
https://cve.org/CVERecord?id=CVE-2025-30192
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30192.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30192
Downstream
Related
Published
2025-07-21T13:15:26Z
Modified
2026-04-10T05:24:41.663936Z
Summary
[none]
Details

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries.

The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers.

The most strict mitigation done when the new setting outgoing.ednssubnetharden (old style name edns-subnet-harden) is enabled.

References

Affected packages