CVE-2026-33600
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-33600 is a NULL pointer dereference vulnerability in PowerDNS Recursor that can be triggered by a malicious authoritative server sending a specially crafted Response Policy Zone (RPZ), resulting in a denial of service. It affects PowerDNS Recursor versions 5.2.0 through 5.2.8, 5.3.0 through 5.3.5, and 5.4.0. The vulnerability was published on April 22, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 4.4–4.9 (Medium), depending on the scoring source (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is a missing consistency check during RPZ (Response Policy Zone) transfer processing, classified as CWE-476 (NULL Pointer Dereference). When a malicious authoritative nameserver sends a crafted RPZ response, the Recursor fails to validate a pointer before dereferencing it, causing a crash. Exploitation requires the attacker to control or compromise an authoritative nameserver that the Recursor is configured to query for RPZ data, placing the attack vector as network-based but requiring high privileges (control over an authoritative server). No public proof-of-concept code has been identified (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation causes the PowerDNS Recursor process to crash, resulting in a denial of service and making DNS resolution unavailable to all clients relying on the affected instance. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. Organizations depending on the affected Recursor for DNS resolution could experience significant service disruption until the process is restarted or patched (GitHub Advisory, PowerDNS Blog).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to control an authoritative nameserver that the target Recursor queries for RPZ data, which significantly limits the attack surface (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate a PowerDNS Recursor instance (versions 5.2.0–5.2.8, 5.3.0–5.3.5, or 5.4.0) configured to use RPZ feeds from an authoritative nameserver.
  2. Gain control of authoritative server: Compromise or operate a DNS authoritative server that the target Recursor is configured to query for RPZ data.
  3. Craft malicious RPZ response: Prepare a specially crafted RPZ zone transfer response that lacks the consistency expected by the Recursor's RPZ processing code, exploiting the missing consistency check.
  4. Trigger the transfer: Cause the Recursor to initiate or receive an RPZ zone transfer (e.g., via AXFR/IXFR) from the malicious authoritative server.
  5. Achieve denial of service: The Recursor dereferences a NULL pointer during RPZ processing, causing the process to crash and DNS resolution to become unavailable (GitHub Advisory, PowerDNS Blog).

Indicators of compromise

  • Process: Unexpected crash or restart of the pdns_recursor process; core dump files generated in the Recursor working directory.
  • Logs: Recursor log entries showing errors or segmentation faults during RPZ zone transfer (AXFR/IXFR) processing; log messages referencing NULL pointer or assertion failures in RPZ-related code paths.
  • Network: Unusual or unexpected RPZ zone transfer (AXFR/IXFR) traffic from an unfamiliar or newly configured authoritative nameserver to the Recursor's RPZ query port.
  • Availability: Sudden loss of DNS resolution for clients using the affected Recursor instance, correlated with RPZ transfer activity.

Mitigation and workarounds

PowerDNS has released patched versions addressing this vulnerability: upgrade to 5.2.9 or later for the 5.2.x branch, 5.3.6 or later for the 5.3.x branch, and 5.4.1 or later for the 5.4.x branch. As a workaround, administrators should restrict RPZ feeds to only trusted, verified authoritative nameservers and implement network segmentation to limit exposure from untrusted nameservers. Monitoring the Recursor process for unexpected crashes can help detect exploitation attempts until patching is complete (PowerDNS Blog, GitHub Advisory).

Community reactions

PowerDNS published a security advisory and blog post on April 22, 2026, coordinating disclosure with the release of patched versions. Red Hat tracked the issue via Bugzilla and their security advisory portal. The vulnerability was also noted in the oss-security mailing list and picked up by Linux distribution security trackers, including a Debian DSA for pdns-recursor. Community reaction has been measured given the medium severity and limited exploitability (PowerDNS Blog, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management