Vulnerability Description
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes
- https://rt.cpan.org/Ticket/Display.html?id=179945
- https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56
- http://www.openwall.com/lists/oss-security/2026/07/20/12
FAQ
What is CVE-2026-64193?
CVE-2026-64193 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR o...
How severe is CVE-2026-64193?
CVE-2026-64193 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-64193?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.