Medium severity5.3NVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
CVE-2026-40209
CVE-2026-40209
Description
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Tumbleweed
< 1.9.15-160000.1.1+ 1 more
- (no CPE)range: < 1.9.15-160000.1.1
- (no CPE)range: < 2.0.7-1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.