CVE-2026-24028 is an out-of-bounds read vulnerability (CWE-126) triggered by a crafted DNS response packet when custom Lua code uses newDNSPacketOverlay for DNS packet parsing; specific affected products are not detailed. Rated Medium with a CVSSv3 score of 5.3, it has low attack complexity and can be exploited remotely without authentication or user interaction. A successful exploit could lead to a denial of service through a system crash, with a potential for information disclosure by accessing unrelated memory. There is currently no evidence of active exploitation, nor are public exploit codes available in common repositories, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9.0, < 1.9.12CPE matchmatch criteria | cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.3CPE matchmatch criteria | cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.