• Bug#1109808: pdns-recursor: CVE-2025-30192

    From Salvatore Bonaccorso@21:1/5 to All on Thu Jul 24 07:30:01 2025
    Source: pdns-recursor
    Version: 5.2.2-2
    Severity: important
    Tags: security upstream
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
    Control: found -1 5.2.2-1

    Hi,

    The following vulnerability was published for pdns-recursor.

    CVE-2025-30192[0]:
    | An attacker spoofing answers to ECS enabled requests sent out by the
    | Recursor has a chance of success higher than non-ECS enabled
    | queries. The updated version include various mitigations against
    | spoofing attempts of ECS enabled queries by chaining ECS enabled
    | requests and enforcing stricter validation of the received answers.
    | The most strict mitigation done when the new setting
    | outgoing.edns_subnet_harden (old style name edns-subnet-harden) is
    | enabled.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-30192
    https://www.cve.org/CVERecord?id=CVE-2025-30192
    [1] https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-04.html

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)