HIGHCVE-2026-27831Published Modified CNA GitHub_M
CVE-2026-27831: rldns Vulnerable to Heap-based Out-of-Bounds Read
rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Version 1.4 contains a patch for the issue.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
Affected packages
- bluedragonsecurity / rldns= 1.3
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
- https://github.com/bluedragonsecurity/rldns/security/advisories/GHSA-fv38-45j4-g9x4
- https://github.com/bluedragonsecurity/rldns-1.3-heap-out-of-bounds-vulnerability-fixed-in-rldns-1.4
- https://github.com/bluedragonsecurity/rldns_archives/blob/main/diff/rldns-1.4.diff
- https://medium.com/@w1sdom/heap-based-buffer-over-read-vulnerability-in-rldns-1-3-5da3bccdc031