Bug#1142503: libnet-dns-perl: CVE-2026-64193 CVE-2026-64194
Salvatore Bonaccorso
carnil at debian.org
Mon Jul 20 20:48:23 BST 2026
Source: libnet-dns-perl
Version: 1.55-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerabilities were published for libnet-dns-perl.
CVE-2026-64193[0]:
| Net::DNS versions through 1.55 for Perl allow remote execution
| injection via EDNS EXTENDED ERROR.
| Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT
| field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the
| raw bytes and passing the result to Perl's eval. There is some
| escaping done for $ and @, but not for backticks. This can be
| exploited for command execution if $pkt->edns->option('EXTENDED-
| ERROR') is called in array context, for example with a payload of
| {0:`"<command>"`} in EXTRA-TEXT.
CVE-2026-64194[1]:
| Net::DNS versions through 1.55 for Perl allow Denial of Service via
| deep DNS compression pointer chains. Net::DNS::DomainName::decode
| follows RFC 1035 compression pointers by recursing into itself with
| no depth limit. It is possible to construct a name which saturates
| the call stack (at least with larger TCP responses), leading to a
| potential Denial of Service. The guard `$link < $offset` prevents
| forward and circular chains, but still allows arbitrarily long
| backward chains. The per-offset cache (`$cache`) is populated at the
| start of each call and short-circuits only re-traverses of the same
| offset - the initial descent through a fresh chain still recurses at
| full depth. A crafted packet can chain two-byte compression
| pointers so that each one points two bytes earlier than the
| previous, producing a chain length of `offset / 2`. For the 14-bit
| pointer field (max offset 16383) this gives up to ~8191 recursive
| frames. For a TCP DNS message the limit is the 16-bit length field
| (~32767 frames). Perl's default C stack handles only a few thousand
| frames; beyond that the process receives SIGSEGV or similar, which
| is a denial-of-service for any application parsing untrusted DNS
| data. The vulnerability is triggered by
| `Net::DNS::Packet->new(\$wire)` i.e. any point where the library
| decodes a DNS message from the network.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-64193
https://www.cve.org/CVERecord?id=CVE-2026-64193
[1] https://security-tracker.debian.org/tracker/CVE-2026-64194
https://www.cve.org/CVERecord?id=CVE-2026-64194
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the pkg-perl-maintainers
mailing list