CVE-2025-59024
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-59024 is a DNS cache poisoning vulnerability in PowerDNS Recursor caused by insufficient verification of data authenticity (CWE-345). Crafted DNS delegations or IP fragments can be used to poison cached delegations in the Recursor, causing it to return incorrect DNS resolution data. Affected versions include PowerDNS Recursor 5.1.0–5.1.7, 5.2.0–5.2.5, and 5.3.0. The vulnerability was disclosed on February 9, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity), meaning the Recursor does not adequately validate the authenticity of DNS delegation responses or IP-fragmented DNS packets before caching them. An unauthenticated, network-based attacker can send specially crafted DNS delegation messages or fragmented IP packets that the Recursor accepts and stores in its cache without proper verification. This attack requires high complexity (e.g., timing or spoofing conditions) but no privileges or user interaction. The official security advisory is published by PowerDNS (PowerDNS Advisory, PowerDNS Blog).

Impact

Successful exploitation allows an attacker to poison the DNS cache of affected PowerDNS Recursor instances, causing clients relying on the resolver to receive fraudulent DNS responses. This can redirect users to malicious or attacker-controlled destinations, enabling phishing, credential theft, or man-in-the-middle attacks. The primary impact is high integrity loss (falsified DNS records), with a low availability impact; there is no confidentiality impact directly from this vulnerability (Red Hat Advisory, PowerDNS Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat Advisory). The EPSS score is very low at 0.005%, reflecting limited near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack complexity is rated High, requiring an attacker to meet specific conditions such as timing or network positioning to successfully inject poisoned responses.

Exploitation steps

  1. Reconnaissance: Identify PowerDNS Recursor instances running vulnerable versions (5.1.0–5.1.7, 5.2.0–5.2.5, or 5.3.0) exposed on the network using port scanning tools targeting UDP/TCP port 53.
  2. Craft malicious delegation or fragmented packet: Prepare a specially crafted DNS delegation response or IP-fragmented DNS packet designed to be accepted by the Recursor as a legitimate authoritative answer without proper authenticity verification.
  3. Race/spoof condition: Exploit the high-complexity attack window — typically by predicting or racing the Recursor's outbound query transaction ID and source port — to inject the crafted response before the legitimate authoritative server responds.
  4. Cache poisoning: The Recursor accepts and caches the malicious delegation, associating a target domain with an attacker-controlled IP address.
  5. Victim redirection: Clients querying the poisoned Recursor for the targeted domain receive the fraudulent IP, redirecting their traffic to attacker-controlled infrastructure (PowerDNS Advisory, PowerDNS Blog).

Indicators of compromise

  • Network: Unexpected or anomalous DNS delegation responses arriving from non-authoritative sources; high volumes of fragmented UDP DNS packets directed at the Recursor; DNS responses with mismatched transaction IDs or source ports in packet captures.
  • Logs: PowerDNS Recursor logs showing unusual delegation caching events or repeated resolution of the same domain to different IP addresses; log entries indicating receipt of fragmented DNS packets from unexpected sources.
  • DNS Cache: Cached DNS records pointing to unexpected or known-malicious IP addresses for well-known domains; sudden changes in cached NS or A records for critical domains without corresponding legitimate TTL expiry.
  • Process/Behavior: Clients reporting unexpected redirections or certificate errors when accessing known-good domains served through the affected Recursor (PowerDNS Advisory).

Mitigation and workarounds

PowerDNS has released patched versions: 5.1.8, 5.2.6, and 5.3.1, which address this vulnerability. Administrators should upgrade to one of these fixed versions immediately (PowerDNS Advisory). As additional mitigations, deploying DNSSEC validation on the Recursor can help authenticate DNS responses and reduce the risk of cache poisoning. Network access controls should be reviewed to restrict DNS query sources to trusted clients where possible, and DNS query patterns should be monitored for anomalies indicative of cache poisoning attempts (Red Hat Advisory).

Community reactions

The vulnerability was covered by runZero in a blog post analyzing PowerDNS Recursor security issues, and was noted in the oss-security mailing list (oss-sec). Debian issued a security advisory (DSA-6045-1) for pdns-recursor addressing this and related issues (Linux Security). Tenable published detection plugins for the vulnerability. Community reaction has been measured given the medium severity and high attack complexity, with no significant controversy or widespread alarm noted.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management