CVE-2026-33610
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-33610 is an uncontrolled resource consumption vulnerability in PowerDNS Authoritative Server that allows a rogue primary DNS server to cause file descriptor exhaustion and eventually a denial of service (DoS) on a PowerDNS secondary server when it forwards a DNS update request. The vulnerability was published on April 22, 2026, and affects PowerDNS Authoritative versions 4.9.0 through 4.9.13 and 5.0.0 through 5.0.3. It carries a CVSS v3.1 base score of 7.5 (High) per NVD, and 5.9 (Medium) per ENISA/GitHub Advisory, reflecting differing assessments of attack complexity (GitHub Advisory, PowerDNS Advisory).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and stems from improper handling of file descriptors during the DNS update forwarding process on PowerDNS secondary servers. When a secondary server forwards a DNS UPDATE request to a primary server, a rogue or malicious primary can manipulate the interaction to prevent proper file descriptor cleanup, causing descriptors to accumulate until the system limit is reached. Exploitation requires network-level access to act as or impersonate a primary server, but no authentication or user interaction is needed (GitHub Advisory, PowerDNS Advisory).

Impact

Successful exploitation results in file descriptor exhaustion on the affected PowerDNS secondary server, ultimately causing a denial of service that prevents the server from processing legitimate DNS queries and requests. There is no confidentiality or integrity impact — the attack is purely an availability concern. Organizations relying on affected secondary servers for DNS resolution could experience service outages affecting all downstream clients (GitHub Advisory, PowerDNS Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.016% (0.000160), placing it in the 1st percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify PowerDNS secondary servers running affected versions (4.9.0–4.9.13 or 5.0.0–5.0.3) that are configured to forward DNS UPDATE requests to a primary server.
  2. Position as rogue primary: Set up or compromise a server that the target secondary is configured to forward DNS updates to, or use network-level techniques (e.g., BGP hijacking, ARP spoofing) to intercept traffic intended for the legitimate primary.
  3. Send malformed/unresponsive DNS UPDATE responses: Respond to forwarded DNS UPDATE requests in a way that prevents the secondary server from properly closing the associated file descriptors (e.g., by holding connections open, sending incomplete responses, or repeatedly triggering new forwarding attempts).
  4. Exhaust file descriptors: Repeat the process until the secondary server's file descriptor limit is reached, at which point it can no longer open new connections or files.
  5. Achieve denial of service: The secondary server becomes unable to process legitimate DNS queries, resulting in a service outage for all clients relying on it (PowerDNS Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: PowerDNS logs showing repeated DNS UPDATE forwarding attempts to a primary server with no successful completion; error messages related to file descriptor limits (e.g., Too many open files, EMFILE errors in system or application logs).
  • Network: Unusual volume of DNS UPDATE (opcode 5) packets being forwarded from the secondary server to a primary; long-lived or unresolved TCP connections to the primary server's IP.
  • Process/System: Rapidly increasing open file descriptor count for the pdns_server process (observable via lsof -p <pid> | wc -l or /proc/<pid>/fd); system alerts from monitoring tools on file descriptor exhaustion.
  • File System: No specific file artifacts expected, but check for unexpected configuration changes to primary server IP addresses in PowerDNS zone settings.

Mitigation and workarounds

PowerDNS has released patched versions 4.9.14 and 5.0.4, which address this vulnerability; upgrading is the recommended remediation (PowerDNS Advisory). As a workaround, administrators should restrict DNS UPDATE forwarding to explicitly trusted and verified primary servers using access control lists, and implement network-level controls (firewalls, IP allowlisting) to limit which hosts can act as primary servers. Monitoring file descriptor usage on DNS servers for anomalies can provide early warning of exploitation attempts. Debian and Fedora package updates have also been issued for affected distributions (Linux Security Debian, Linux Security Fedora).

Community reactions

PowerDNS published a security advisory and blog post on April 22, 2026, disclosing the vulnerability and providing patched versions (PowerDNS Blog). The vulnerability was also disclosed on the oss-security mailing list and picked up by downstream Linux distributions including Debian and Fedora, which issued updated packages (oss-sec). No notable independent researcher commentary or significant social media discussion has been observed beyond standard vulnerability tracking and distribution advisories.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns

Affected

sid

pdns: 5.0.4-1

Fixed

trixie

pdns: 4.9.14-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pdns

Unknown

devel

pdns

Unknown

focal (esm-apps)

pdns

Unknown

jammy

pdns

Unknown

jammy (esm-apps)

pdns

Unknown

noble

pdns

Unknown

noble (esm-apps)

pdns

Unknown

resolute

pdns

Unknown

Alpine

Fixed

edge

pdns: 5.0.4-r0

Fixed

v3.23

pdns: 5.0.4-r0

Fixed

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19624HIGH7.8
  • Linux Debian logoLinux Debian
  • network-manager-l2tp
NoYesSep 14, 2026
CVE-2026-19499HIGH7.7
  • Linux Debian logoLinux Debian
  • glibc-langpack-bs
NoYesSep 14, 2026
CVE-2026-19816HIGH7.1
  • Linux Debian logoLinux Debian
  • PackageKit-glib
NoYesSep 14, 2026
CVE-2026-82035HIGH7.1
  • Linux Debian logoLinux Debian
  • pymupdf
NoNoSep 14, 2026
CVE-2026-19542MEDIUM5.6
  • Linux Debian logoLinux Debian
  • glibc-langpack-ka
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management