Logo
vulnerabilityCVE-2026-27854
Name
CVE-2026-27854
Source
NVD ( link)Debian ( link)
Description
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-free and potentially a crash resulting in denial of service.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dnsdist
Exploitable

Vulnerability Ratings#


4.8
CVSSv31
7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
openwrt
master
2.0.6-r1
Not Affected