Concurrency and locking defects in GSS-TSIG
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HPowerdns Authoritative
APPPowerdns4.7.0 – 4.9.15 (excl.)5.0.0 – 5.0.5 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2020-24698CRITICAL9.8PL ✓same product
PowerDNS Authoritative: double-free via GSS-TSIG umożliwia RCE
CVE-2026-42001HIGH7.5same product
Insufficient Validation of Autoprimary SOA Queries
CVE-2026-33608HIGH7.4same product
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but ...
CVE-2020-24696HIGH8.1same product
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A...
CVE-2020-24697HIGH7.5same product
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A...