Unrated severityNVD Advisory· Published Jun 26, 2026
Debian dnsdist: An attacker might be able to cause outgoing TCP connections to backend to be stu…
CVE-2026-40209
Description
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.