CVE-2020-12667
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2020-12667 affects Knot Resolver versions before 5.1.1, allowing traffic amplification via a crafted DNS answer from an attacker-controlled server, known as an 'NXNSAttack' issue. The vulnerability was discovered in May 2020 and is triggered by random subdomains in the NSDNAME in NS records (NVD, Knot Resolver).

Technical details

The vulnerability exploits the DNS delegation mechanism to force DNS resolvers to generate multiple DNS queries to authoritative servers of the attacker's choice. The attack uses glueless delegation, where the resolver receives only names of authoritative DNS servers without their IP addresses, forcing additional queries. The packet amplification factor (PAF) varies by implementation - BIND 9.12.3 resolver showed a PAF of 1000x, while Knot Resolver 5.1.0 limited it to the order of tens (CZ NIC Blog).

Impact

The vulnerability enables attackers to use standard-compliant DNS resolvers as amplifiers for random subdomain attacks, potentially leading to significant traffic amplification and denial of service conditions. The attack's effectiveness varies based on the resolver implementation and its resource capacity (CZ NIC Blog).

Exploitability

The vulnerability can be exploited by sending a DNS query to a vulnerable resolver and providing a specially crafted answer from an authoritative server under attacker's control. This DNS protocol vulnerability affects most recursive DNS resolvers, making it a widespread issue (OSS Security).

Mitigation and workarounds

The primary mitigation is upgrading to Knot Resolver version 5.1.1 or later, which includes specific protections against this attack. The fix implements limits on the number of names resolved when processing a single delegation. Additionally, deploying DNSSEC and enabling Aggressive Use of DNSSEC-Validated Cache (RFC 8198) can help limit the impact of random subdomain attacks (CZ NIC Blog, Knot Resolver).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management