CVE-2025-59023: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-59023 is a DNS cache poisoning vulnerability in PowerDNS Recursor that allows unauthenticated remote attackers to poison cached delegations using crafted delegations or IP fragments. It affects PowerDNS Recursor versions 5.1.0–5.1.7, 5.2.0–5.2.5, and 5.3.0. The vulnerability was first tracked in February 2026 and the official advisory was published by PowerDNS. It carries a CVSS v3.1 base score of 8.2 (High) (Red Hat Advisory, PowerDNS Advisory).

Technical details

The root cause is classified under CWE-345 (Insufficient Verification of Data Authenticity) and CWE-294 (Authentication Bypass by Capture-replay), meaning the Recursor fails to adequately validate the authenticity of DNS delegation responses or IP-fragmented packets before caching them. An attacker can send crafted DNS delegation responses or manipulate IP fragments to inject malicious records into the Recursor's delegation cache without any authentication. This is a network-accessible attack requiring no privileges or user interaction, making it exploitable by any attacker with network access to the resolver. The attack aligns with CAPEC-142 (DNS Cache Poisoning) and CAPEC-141 (Cache Poisoning) patterns (PowerDNS Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an attacker to poison the DNS delegation cache of affected PowerDNS Recursor instances, redirecting users to attacker-controlled destinations and enabling man-in-the-middle attacks against DNS-dependent services. The primary impact is high integrity loss — DNS responses served to clients can be falsified — with a low availability impact due to potential service disruption. Confidentiality is not directly impacted, but downstream effects such as credential harvesting via redirected traffic are a realistic consequence (Red Hat Advisory, PowerDNS Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at approximately 0.005%, reflecting limited current exploitation probability. No threat actor attribution has been reported (PowerDNS Advisory).

Exploitation steps

  1. Reconnaissance: Identify PowerDNS Recursor instances running vulnerable versions (5.1.0–5.1.7, 5.2.0–5.2.5, or 5.3.0) using network scanning tools such as Shodan, Censys, or nmap with DNS service fingerprinting.
  2. Craft malicious delegation response: Prepare a DNS response containing a crafted delegation (NS record pointing to an attacker-controlled nameserver) or manipulate IP fragments to inject forged delegation data.
  3. Trigger delegation lookup: Cause the target Recursor to perform a delegation lookup for a domain under attacker influence, either by sending a DNS query for a subdomain of an attacker-controlled zone or by exploiting IP fragmentation to inject forged responses.
  4. Poison the delegation cache: The Recursor, due to insufficient authenticity verification, accepts and caches the malicious delegation, associating a legitimate domain with attacker-controlled nameservers.
  5. Redirect victim traffic: Subsequent DNS queries from clients using the poisoned Recursor are resolved using the attacker's nameserver, enabling traffic redirection, phishing, or man-in-the-middle interception (PowerDNS Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unexpected or anomalous DNS delegation responses (NS records) pointing to unknown or suspicious nameservers; unusual IP-fragmented UDP packets directed at the Recursor's DNS port (53/UDP).
  • Logs: PowerDNS Recursor logs showing delegation cache updates from unexpected source IPs or for domains not recently queried; repeated delegation lookups for the same zone from external sources.
  • DNS Cache: Presence of unexpected NS records in the Recursor's delegation cache (inspectable via rec_control dump-cache); cached delegations pointing to IP addresses not associated with legitimate authoritative nameservers.
  • Process/Behavior: Sudden increase in NXDOMAIN or resolution failures for previously working domains, which may indicate poisoned delegations redirecting to non-functional nameservers (PowerDNS Advisory).

Mitigation and workarounds

PowerDNS has released patched versions: 5.1.8, 5.2.6, and 5.3.1, which address this vulnerability. Organizations should upgrade to one of these fixed versions as the primary remediation. As a network-level workaround, restrict DNS query sources to trusted clients and implement BCP38 (ingress filtering) to reduce IP spoofing risk. Monitoring DNS query logs for suspicious delegation patterns or unusual IP fragments is also recommended (PowerDNS Advisory, Red Hat Advisory).

Community reactions

The PowerDNS blog published the security advisory (2025-06) detailing the vulnerability and patched versions. Debian issued a security advisory (DSA-6045-1) for pdns-recursor, and the issue was discussed on the oss-security mailing list. runZero published a blog post covering the vulnerability in the context of PowerDNS Recursor exposure. Community coverage has been moderate, with aggregation by Tenable (Nessus plugins 271577 and 271978), VulDB, and Linux security news outlets (PowerDNS Blog, runZero Blog, oss-sec).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns-recursor

Affected

sid

pdns-recursor: 5.3.1-1

Fixed

trixie

pdns-recursor: 5.2.6-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pdns-recursor

Unknown

devel

pdns-recursor

Unknown

focal (esm-apps)

pdns-recursor

Unknown

jammy

pdns-recursor

Unknown

jammy (esm-apps)

pdns-recursor

Unknown

noble

pdns-recursor

Unknown

noble (esm-apps)

pdns-recursor

Unknown

resolute

pdns-recursor

Unknown

Alpine

Fixed

edge

pdns-recursor: 5.3.0-r0

Fixed

v3.22

pdns-recursor: 5.2.5-r0

Fixed

v3.23

pdns-recursor: 5.3.0-r0

Fixed

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management