FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

dnsdist -- Denial of service via crafted DoH exchange

Affected packages
null < null

Details

VuXML ID 7e7a32e7-2901-11f0-ab20-b42e991fc52e
Discovery 2025-04-29
Entry 2025-05-04

security@open-xchange.com reports:

When DNSdist is configured to provide DoH via the nghttp2provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to temporarily switch to the h2o provider until DNSdist has been upgraded to a fixed version. We would like to thank Charles Howes for bringing this issue to our attention.

References

CVE Name CVE-2025-30194
URL https://nvd.nist.gov/vuln/detail/CVE-2025-30194