AI Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2025-30192
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-30192 is a DNS spoofing vulnerability in PowerDNS Recursor affecting instances configured to send EDNS Client Subnet (ECS) enabled queries. When ECS is enabled, an attacker has a statistically higher chance of successfully spoofing DNS answers compared to non-ECS queries, due to insufficient verification of data authenticity (CWE-345). The vulnerability was published on July 21, 2025, and affects PowerDNS Recursor versions prior to 5.0.12, 5.1.6, and 5.2.4. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). When PowerDNS Recursor sends outgoing queries with ECS (EDNS Client Subnet) options, the additional subnet information included in the query increases the attack surface for off-path spoofing, as the attacker can more precisely predict or match query parameters to craft a forged response. The vulnerability is exploitable remotely without authentication or user interaction, targeting the DNS resolution path between the Recursor and upstream resolvers. The patched versions introduce mitigations including chaining ECS-enabled requests and enforcing stricter validation of received answers; the most stringent protection is activated by enabling the new outgoing.edns_subnet_harden setting (formerly edns-subnet-harden) (PowerDNS Advisory, Red Hat Bugzilla).

Impact

Successful exploitation could allow an attacker to poison the DNS cache of the affected Recursor, redirecting users to malicious destinations or enabling man-in-the-middle attacks against DNS-dependent services. The primary impact is on availability and integrity of DNS resolution — confidentiality is not directly affected. Downstream clients relying on the poisoned Recursor could be redirected to attacker-controlled infrastructure, potentially enabling phishing, credential theft, or interception of sensitive traffic (Red Hat Advisory, ENISA EUVD).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly Intelligence).

Exploitation steps

  1. Identify target: Locate a PowerDNS Recursor instance (versions prior to 5.0.12, 5.1.6, or 5.2.4) configured with ECS (EDNS Client Subnet) enabled for outgoing queries.
  2. Monitor or predict queries: Position on a network path or use timing/statistical methods to observe or predict outgoing ECS-enabled DNS queries from the Recursor to upstream authoritative servers.
  3. Craft spoofed response: Forge a DNS response that matches the query ID, source port, and ECS subnet parameters of the outgoing query. The ECS option increases the predictability of query parameters, raising the probability of a successful spoof compared to standard queries.
  4. Race the legitimate response: Send the forged response to the Recursor before the legitimate upstream answer arrives, exploiting the reduced entropy introduced by ECS to win the race condition.
  5. Achieve cache poisoning: If successful, the Recursor caches the malicious DNS record, causing downstream clients to resolve the targeted domain to an attacker-controlled IP address (PowerDNS Advisory).

Indicators of compromise

  • Network: Unexpected or duplicate DNS responses arriving for ECS-enabled outgoing queries; anomalous UDP traffic targeting the Recursor's outgoing query port from external sources.
  • Logs: PowerDNS Recursor logs showing resolution of known-good domains to unexpected IP addresses; repeated resolution failures or cache inconsistencies for ECS-enabled queries.
  • DNS Cache: Presence of unexpected or short-TTL records in the Recursor cache for high-value domains; discrepancies between cached records and authoritative DNS responses when manually queried.

Mitigation and workarounds

Upgrade PowerDNS Recursor to one of the patched versions: 5.0.12, 5.1.6, or 5.2.4. After upgrading, enable the new outgoing.edns_subnet_harden setting (legacy name: edns-subnet-harden) for the strictest protection against ECS spoofing. As an interim measure, disabling ECS on outgoing queries eliminates the elevated spoofing risk. Additionally, deploying DNSSEC validation on the Recursor provides an independent layer of protection against forged DNS responses (PowerDNS Advisory, Red Hat Bugzilla).

Community reactions

Red Hat has tracked the vulnerability via Bugzilla and assigned it medium severity for their products. ENISA has catalogued the vulnerability in the EU Vulnerability Database (EUVD-2025-22089). No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability aggregator coverage (Red Hat Advisory, ENISA EUVD).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns-recursor

Affected

sid

pdns-recursor: 5.2.4-2

Fixed

trixie

pdns-recursor: 5.2.4-2

Fixed

Alpine

Fixed

edge

pdns-recursor: 5.2.5-r0

Fixed

v3.22

pdns-recursor: 5.2.2-r0

Fixed

v3.23

pdns-recursor: 5.2.5-r0

Fixed

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91990HIGH8.7
  • Linux Debian logoLinux Debian
  • python3-tornado
NoNoSep 15, 2026
CVE-2026-91992HIGH8.2
  • Linux Debian logoLinux Debian
  • python-tornado
NoNoSep 15, 2026
CVE-2026-91991MEDIUM6.3
  • Linux Debian logoLinux Debian
  • python-tornado
NoNoSep 15, 2026
CVE-2026-91986MEDIUM5.3
  • Linux Debian logoLinux Debian
  • rust-toolset:rhel8::rust-analyzer
NoNoSep 15, 2026
CVE-2026-48785MEDIUM4.8
  • Linux Debian logoLinux Debian
  • apptainer-sle15_7
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management