Vulnerability Description
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-30193?
CVE-2025-30193 is a vulnerability with a CVSS score of 7.5 (HIGH). In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TC...
How severe is CVE-2025-30193?
CVE-2025-30193 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-30193?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.