CVE-2025-59030: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-59030 is a cache invalidation vulnerability in PowerDNS Recursor that allows an unauthenticated remote attacker to remove cached DNS records by sending a NOTIFY query over TCP. It affects PowerDNS Recursor versions 5.1.0–5.1.8, 5.2.0–5.2.6, and 5.3.0–5.3.2. The vulnerability was published on December 9, 2025, with patches released concurrently. It carries a CVSS v3.1 base score of 7.5 (High) (PowerDNS Advisory, ENISA EUVD).

Technical details

The vulnerability is classified under CWE-276 (Incorrect Default Permissions), indicating that the PowerDNS Recursor improperly handles NOTIFY queries received over TCP without enforcing appropriate access controls. Under normal DNS operation, NOTIFY messages are used by authoritative servers to signal zone changes to secondary servers; however, in this case, the Recursor incorrectly processes such queries and triggers the eviction of cached records. No authentication or special privileges are required, and the attack vector is network-accessible with low complexity. The flaw allows any remote host to manipulate the resolver's cache state by crafting and sending TCP-based NOTIFY packets (PowerDNS Advisory, PowerDNS Blog).

Impact

Successful exploitation degrades DNS resolution performance by forcing the Recursor to re-resolve records that were previously cached, resulting in a denial-of-service condition for dependent systems and services. Additionally, cache invalidation can open a window for DNS poisoning attacks, where an attacker could attempt to inject malicious records after flushing legitimate ones. There is no confidentiality or integrity impact on the resolver itself, but downstream services relying on cached DNS responses may experience disruption or be exposed to spoofed DNS responses (PowerDNS Advisory, ENISA EUVD).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (ENISA EUVD). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021%, reflecting a low probability of exploitation in the near term. Despite the low exploitation evidence, the attack requires no authentication and has low complexity, making it trivially executable by any network-accessible attacker.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible PowerDNS Recursor instances running versions 5.1.0–5.1.8, 5.2.0–5.2.6, or 5.3.0–5.3.2 using network scanning tools such as Shodan, Censys, or nmap targeting TCP port 53.
  2. Craft NOTIFY query: Construct a DNS NOTIFY query packet (opcode 4) targeting any zone name, formatted for transmission over TCP (with the standard 2-byte length prefix).
  3. Send NOTIFY over TCP: Transmit the crafted NOTIFY query to the target Recursor's TCP port 53 without any authentication or prior session establishment.
  4. Trigger cache eviction: The Recursor incorrectly processes the NOTIFY message and removes the associated cached DNS records, degrading resolution performance.
  5. Optionally follow with poisoning attempt: After cache eviction, attempt to inject malicious DNS responses for the flushed records to redirect traffic or intercept communications (PowerDNS Advisory).

Indicators of compromise

  • Network: Unexpected TCP connections to port 53 on the PowerDNS Recursor from untrusted or external IP addresses; DNS NOTIFY packets (opcode 4) arriving over TCP from non-authoritative sources.
  • Logs: Recursor logs showing repeated NOTIFY query processing events from unexpected source IPs; increased cache miss rates or cache flush events in DNS query logs.
  • Process/Behavior: Unusual spikes in DNS resolution latency or upstream query volume, indicating cache has been repeatedly invalidated; DNS resolution failures for records that should be cached (PowerDNS Advisory).

Mitigation and workarounds

Upgrade PowerDNS Recursor to the patched versions: 5.1.9 or later (for 5.1.x deployments), 5.2.7 or later (for 5.2.x deployments), or 5.3.3 or later (for 5.3.x deployments). As a network-level workaround where immediate patching is not feasible, restrict TCP access to port 53 on the Recursor to only trusted authoritative name servers using firewall rules or ACLs. Monitor for unusual cache invalidation patterns and DNS query anomalies as an interim detection measure (PowerDNS Advisory, PowerDNS Blog).

Community reactions

PowerDNS published a security advisory and blog post on December 8–9, 2025, disclosing the vulnerability alongside a companion advisory (2025-07). The issue was also disclosed via the oss-security mailing list and picked up by Linux distribution security channels including Debian and Fedora, which issued updated packages (oss-sec, Linux Security). Tenable released Nessus detection plugins (IDs 277742 and 278085) shortly after disclosure (Tenable).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns-recursor

Affected

sid

pdns-recursor: 5.3.3-1

Fixed

trixie

pdns-recursor: 5.2.7-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pdns-recursor

Unknown

devel

pdns-recursor

Unknown

focal (esm-apps)

pdns-recursor

Unknown

jammy

pdns-recursor

Unknown

jammy (esm-apps)

pdns-recursor

Unknown

noble

pdns-recursor

Unknown

noble (esm-apps)

pdns-recursor

Unknown

resolute

pdns-recursor

Unknown

Alpine

Fixed

edge

pdns-recursor: 5.3.1-r1

Fixed

v3.22

pdns-recursor: 5.2.6-r0

Fixed

v3.23

pdns-recursor: 5.3.1-r1

Fixed

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management