CVE-2026-0398: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-0398 is a dual-nature vulnerability in PowerDNS Recursor that allows unauthenticated remote attackers to cause increased resource consumption via crafted DNS zones and to perform cache poisoning via crafted CNAME chains. It was published on February 9, 2026, and affects PowerDNS Recursor versions 5.1.0 through 5.1.9, 5.2.x through 5.2.7, and 5.3.0 through 5.3.4. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), though Feedly's category estimate rates it as HIGH given its network-accessible, no-authentication-required nature (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where PowerDNS Recursor fails to adequately constrain resource consumption when processing specially crafted DNS zones. A second attack vector involves crafted CNAME chains that can manipulate the resolver's cache, resulting in cache poisoning. Both attack vectors are exploitable over the network without authentication or user interaction, making them accessible to any attacker who can send DNS queries to the resolver. The PowerDNS security advisory (2026-01) provides the authoritative technical description of both issues (PowerDNS Advisory, PowerDNS Blog).

Impact

Exploitation of the resource exhaustion vector can degrade or disrupt DNS resolution services, causing availability issues for all downstream clients relying on the affected Recursor instance. The cache poisoning vector via crafted CNAME chains can cause DNS clients to receive incorrect or malicious DNS records, potentially redirecting traffic to attacker-controlled infrastructure and enabling man-in-the-middle attacks or phishing scenarios. Confidentiality and integrity of DNS responses are at risk from the cache poisoning component, while availability is at risk from the resource exhaustion component (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat Advisory). The EPSS score is very low at 0.01%, reflecting limited current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (IDs 298462 and 299057) and Qualys (ID 692218), indicating scanner coverage for affected deployments.

Indicators of compromise

  • Network: Unusual spikes in DNS query volume directed at the Recursor, particularly queries referencing zones with deeply nested or circular CNAME chains; anomalous outbound DNS resolution patterns from the Recursor to authoritative servers.
  • Logs: PowerDNS Recursor logs showing excessive recursion depth warnings, repeated resolution of the same CNAME chains, or high CPU/memory usage alerts tied to specific query patterns.
  • Process: Elevated CPU or memory consumption by the pdns_recursor process without a corresponding increase in legitimate query load.
  • Cache: Unexpected or anomalous DNS records appearing in the Recursor's cache, particularly for domains not recently queried by clients, which may indicate successful cache poisoning.

Mitigation and workarounds

PowerDNS has released patched versions addressing CVE-2026-0398: upgrade to Recursor 5.1.10, 5.2.8, or 5.3.5 or later as appropriate for your branch (PowerDNS Advisory). As interim mitigations, administrators should implement network-level access controls to restrict DNS queries to trusted sources only, apply rate limiting on queries from untrusted sources, and monitor Recursor instances for unusual resource consumption or cache anomalies. A Debian security advisory (DSA-6134-1) has also been issued for package maintainers (Linux Security).

Community reactions

PowerDNS published a security advisory blog post on February 9, 2026, coinciding with the CVE disclosure (PowerDNS Blog). Red Hat tracked the issue via Bugzilla and issued a security advisory, and Debian issued DSA-6134-1 for the pdns-recursor package. The vulnerability was discussed on the oss-security mailing list shortly after disclosure (oss-sec). No significant social media controversy or notable independent researcher commentary has been observed beyond standard vulnerability aggregator coverage.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns-recursor

Affected

sid

pdns-recursor: 5.3.5-1

Fixed

trixie

pdns-recursor: 5.2.8-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pdns-recursor

Unknown

devel

pdns-recursor

Unknown

focal (esm-apps)

pdns-recursor

Unknown

jammy

pdns-recursor

Unknown

jammy (esm-apps)

pdns-recursor

Unknown

noble

pdns-recursor

Unknown

noble (esm-apps)

pdns-recursor

Unknown

resolute

pdns-recursor

Unknown

Alpine

Fixed

edge

pdns-recursor: 5.3.5-r0

Fixed

v3.23

pdns-recursor: 5.3.5-r0

Fixed

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management