High [CVE-2026-81928] Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records
This high-severity Red Hat Linux advisory covers CVE-2026-81928 affecting Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in Net::DNS versions before 1.57 for Perl. An attacker can cause a denial of service (DoS) by sending a specially crafted DNS message with a misplaced Transaction Signature (TSIG) record.
When a system using Net::DNS, such as a forwarder or proxy, attempts to re-encode this message, it can lead to unbounded recursion and memory exhaustion, ultimately terminating the process.
This vulnerability arises because the `sig_data` function fails to properly remove TSIG records from all sections of a DNS message, violating RFC 8945 section 5.2 requirements. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
Affected products named by the advisory: Red Hat package: perl-net-dns.
- < 1.57
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- To mitigate this issue, restrict network access to DNS services utilizing `perl-Net-DNS` to trusted clients or internal networks only, thereby limiting exposure. If the DNS service is not required to act as a forwarder or proxy, disable this functionality to prevent the vulnerable code path from being exercised.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.