Source: pdns-recursor Version: 5.4.4-1 Severity: important Tags: security upstream Forwarded: https://github.com/PowerDNS/pdns/pull/17748 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for pdns-recursor. It ws not important renough to get in in the last round of updates AFAIU. CVE-2026-52684[0]: | If the auth responds very slowly and the records expire in between, | the capping of TTLs is not enforced for lack of data. This does not | happen on regular resolve as then then the child records are used | immediately if not expired and thus valid, or the records are | expired, and in that case not used. So this case can only happen | if almost expired records are used to refresh the authoritative NS | records. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-52684 https://www.cve.org/CVERecord?id=CVE-2026-52684 [1] https://github.com/PowerDNS/pdns/pull/17748 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

