Hello,

The following is a report of a remotely triggerable heap buffer
overflow in Knot Resolver's DNS-over-QUIC (DoQ) receive path, leading
to remote code execution. The issue was reported to CZ.NIC on
2026-06-08 and fixed in Knot Resolver 6.4.1, released on 2026-07-22.

It seems the vendor did not request a CVE for this issue, so I am asking for 
one.


Reply via email to