Cyber Security News

PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition

A high-severity vulnerability (CVE-2025-30194) in PowerDNS DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to trigger denial-of-service (DoS) conditions by exploiting flaws in its DNS-over-HTTPS (DoH) implementation. 

The vulnerability, disclosed in PowerDNS Security Advisory, affects DNSdist versions 1.9.0 through 1.9.8 when configured to use the nghttp2 library for DoH processing.

Successful exploitation crashes the DNSdist service via a double-free memory corruption event, disrupting DNS resolution for dependent systems.

High-Severity DoS in DNSdist via nghttp2 DoH

The vulnerability stems from improper memory management when handling maliciously crafted DoH exchanges. 

Attackers exploiting this flaw send specially structured HTTP/2 requests that cause DNSdist to attempt freeing the same memory region twice-a critical error classified as CWE-416 (Use After Free). 

This triggers a segmentation fault, terminating the DNSdist process entirely. The attack requires no authentication and can be executed remotely over the network, earning it a CVSS v3.1 score of 7.5.

Notably, the issue only manifests in configurations using the nghttp2 provider for incoming DoH traffic, a default setting since DNSdist 1.9.0. 

Systems relying on the legacy h2o library or earlier DNSdist versions remain unaffected. 

PowerDNS engineers traced the root cause to an edge-case interaction between nghttp2’s request handling and DNSdist’s internal resource management logic, exacerbated by certain HTTP/2 frame sequences.

With DNSdist deployed in critical infrastructure roles-including recursive resolver farms, authoritative DNS clusters, and DDoS-protected networks-this vulnerability poses significant operational risks. 

An unpatched instance could suffer prolonged outages, as restarting the crashed service provides only temporary relief until the next attack

The discovery of this vulnerability is credited to Charles Howes, who brought the issue to the attention of PowerDNS. 

The swift response from PowerDNS in releasing a fixed version demonstrates the importance of community involvement in maintaining the security of critical infrastructure software.

Risk FactorsDetails
Affected ProductsPowerDNS DNSdist versions 1.9.0 to 1.9.8 (fixed in 1.9.9)
ImpactDenial of service (DoS)
Exploit PrerequisitesDNSdist must be configured to provide DoH using the nghttp2 provider
CVSS 3.1 Score7.5 (High)

Workaround

To mitigate this vulnerability, users are advised to upgrade to the patched version 1.9.9 of DNSdist. 

For those unable to upgrade immediately, a temporary workaround is to switch to the h2o provider until the update can be implemented. 

This ensures that DoH services remain operational while preventing exploitation of the vulnerability. The PowerDNS DNSdist vulnerability highlights the importance of keeping software up to date, especially for critical infrastructure components like DNS services. 

As the use of DoH continues to grow, ensuring the security of these services is paramount to prevent disruptions and maintain network integrity. 

Users are encouraged to apply the patch or implement the workaround to protect against potential attacks.

Are you from the SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago