CVE-2025-59029: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-59029 is a Reachable Assertion (CWE-617) vulnerability in PowerDNS Recursor that allows unauthenticated remote attackers to trigger a denial of service by crashing the DNS service. It affects PowerDNS Recursor versions 5.3.0 and 5.3.1. The vulnerability was published on December 9, 2025, with a patch available in version 5.3.2. It carries a CVSS v3.1 base score of 5.3 (Medium) (PowerDNS Advisory, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-617 (Reachable Assertion), meaning an attacker can cause the application to reach an internal assertion check that fails, resulting in an abnormal process termination. The attack is a two-stage process: first, the attacker sends crafted DNS records to the resolver, waits for those records to be inserted into the Recursor's record cache, and then sends a follow-up DNS query with the query type (qtype) set to ANY. This combination triggers an assertion failure within the Recursor process, causing it to crash. No authentication, privileges, or user interaction are required, and the attack is executable over the network with low complexity (PowerDNS Advisory, ENISA EUVD).

Impact

Successful exploitation crashes the PowerDNS Recursor process, causing a complete loss of DNS resolution availability for all clients relying on the affected resolver. The impact is limited to availability — there is no confidentiality or integrity impact. Organizations depending on the affected Recursor instances for DNS infrastructure could experience service outages affecting all downstream systems and users until the service is restarted or failover occurs (PowerDNS Advisory, ENISA EUVD).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (ENISA EUVD, PowerDNS Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible PowerDNS Recursor instances running versions 5.3.0 or 5.3.1 using network scanning tools or DNS banner analysis.
  2. Craft malicious DNS records: Prepare DNS records specifically crafted to trigger the assertion failure condition when later queried with qtype=ANY.
  3. Populate the cache: Send DNS queries that cause the crafted records to be resolved and inserted into the Recursor's record cache. This may require controlling or spoofing an authoritative DNS server that responds with the malicious records.
  4. Trigger the assertion failure: Send a DNS query to the Recursor with qtype set to ANY for the cached domain. The Recursor processes the cached crafted records in response to the ANY query, hits the internal assertion check, and crashes.
  5. Result: The Recursor process terminates, causing a denial of service for all DNS resolution handled by that instance (PowerDNS Advisory).

Indicators of compromise

  • Logs: Unexpected PowerDNS Recursor process crash logs or core dump files; log entries showing assertion failure messages immediately following ANY-type DNS queries.
  • Network: Unusual volume of DNS queries with qtype=ANY directed at the Recursor; DNS queries for uncommon or newly registered domains followed shortly by ANY queries for the same domains.
  • Process: Sudden termination or restart of the pdns_recursor process without administrative action; monitoring alerts for Recursor service restarts.
  • File System: Presence of core dump files in the Recursor working directory following unexpected crashes (PowerDNS Advisory).

Mitigation and workarounds

The primary remediation is to upgrade PowerDNS Recursor to version 5.3.2 or later, which contains the fix for this assertion failure. Only versions 5.3.0 and 5.3.1 are affected; organizations running earlier versions in other branches are not impacted by this specific CVE. No configuration-based workaround has been published; upgrading is the recommended and only confirmed mitigation (PowerDNS Advisory, PowerDNS Blog).

Community reactions

PowerDNS published a security advisory and blog post on December 8–9, 2025, disclosing the vulnerability alongside advisory 2025-08. The disclosure was also reported to the oss-security mailing list, following standard coordinated disclosure practices. Coverage has been limited to security aggregators and Linux distribution security channels, with Fedora issuing updates for affected packages in 2026 (PowerDNS Blog, oss-sec).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns-recursor

Fixed

sid

pdns-recursor: 5.3.3-1

Fixed

trixie

pdns-recursor

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pdns-recursor

Unknown

devel

pdns-recursor

Unknown

focal (esm-apps)

pdns-recursor

Unknown

jammy

pdns-recursor

Unknown

jammy (esm-apps)

pdns-recursor

Unknown

noble

pdns-recursor

Unknown

noble (esm-apps)

pdns-recursor

Unknown

resolute

pdns-recursor

Unknown

Alpine

Fixed

edge

pdns-recursor: 5.3.1-r1

Fixed

v3.23

pdns-recursor: 5.3.1-r1

Fixed

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management