]> git.ipfire.org Git - thirdparty/pdns.git/commitdiff
documentation and secpoll update for auth 4.9.16, 5.0.6 and 5.1.2 17592/head
authorMiod Vallat <miod.vallat@powerdns.com>
Thu, 25 Jun 2026 06:04:49 +0000 (08:04 +0200)
committerMiod Vallat <miod.vallat@powerdns.com>
Thu, 25 Jun 2026 06:04:49 +0000 (08:04 +0200)
Signed-off-by: Miod Vallat <miod.vallat@powerdns.com>
docs/changelog/4.9.rst
docs/changelog/5.0.rst
docs/changelog/5.1.rst
docs/secpoll.zone
docs/security-advisories/powerdns-advisory-2026-07.rst [new file with mode: 0644]

index 95cdb06b4b218fbb2383b94ed3845aded2f7b952..4272ab41bae2db41dcd87121336ef53ee748d21b 100644 (file)
@@ -1,6 +1,21 @@
 Changelogs for 4.9.x
 ====================
 
+.. changelog::
+  :version: 4.9.16
+  :released: 25th of June 2026
+
+  This is release 4.9.16 of the Authoritative Server.
+  It contains a security fix only.
+
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x.
+
+  .. change::
+    :tags: Bug Fixes
+    :pullreq: 17591
+
+    Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
+
 .. changelog::
   :version: 4.9.15
   :released: 20th of May 2026
index fb49065026f8ca6f0789c4aaeaa3c5f6bcec7f18..eddcd1fb027083b9fd8d19cc8cdadca8da5685c6 100644 (file)
@@ -1,6 +1,21 @@
 Changelogs for 5.0.x
 ====================
 
+.. changelog::
+  :version: 5.0.6
+  :released: 25th of June 2026
+
+  This is release 5.0.6 of the Authoritative Server.
+  It contains a security fix only.
+
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+
+  .. change::
+    :tags: Bug Fixes
+    :pullreq: 17590
+
+    Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
+
 .. changelog::
   :version: 5.0.5
   :released: 20th of May 2026
@@ -8,7 +23,7 @@ Changelogs for 5.0.x
   This is release 5.0.5 of the Authoritative Server.
   It contains bug fixes and security fixes.
 
-  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x.
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
 
   .. change::
     :tags: Bug Fixes
@@ -107,7 +122,7 @@ Changelogs for 5.0.x
   This is release 5.0.4 of the Authoritative Server.
   It contains security fixes only.
 
-  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x.
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
 
   .. change::
     :tags: Bug Fixes
index 4f326d8aba5cf44ffb1d6772ada2f527d1a1cdba..1aeb057d3e848cd719a13ce62438385a11d44845 100644 (file)
@@ -1,6 +1,21 @@
 Changelogs for 5.1.x
 ====================
 
+.. changelog::
+  :version: 5.1.2
+  :released: 25th of June 2026
+
+  This is release 5.1.2 of the Authoritative Server.
+  It contains a security fix only.
+
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
+
+  .. change::
+    :tags: Bug Fixes
+    :pullreq: 17589
+
+    Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
+
 .. changelog::
   :version: 5.1.1
   :released: 8th of June 2026
@@ -8,7 +23,7 @@ Changelogs for 5.1.x
   This is release 5.1.1 of the Authoritative Server.
   It contains an important bugfix for users of the LMDB backend.
 
-  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
 
   .. change::
     :tags: Bug Fixes
@@ -23,7 +38,7 @@ Changelogs for 5.1.x
   This is release 5.1.0 of the Authoritative Server.
   It provides many small new features and improvements, as well as bug fixes.
 
-  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
 
   .. change::
     :tags: Improvements
@@ -146,7 +161,7 @@ Changelogs for 5.1.x
   It provides many small new features and improvements, as well as bug fixes,
   including fixes for the PowerDNS Security Advisory 2026-05.
 
-  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
 
   .. change::
     :tags: New Features
@@ -315,7 +330,7 @@ Changelogs for 5.1.x
   This is release 5.1.0-alpha1 of the Authoritative Server.
   It provides many small new features and improvements, as well as bug fixes.
 
-  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+  Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
 
   .. change::
     :tags: New Features
index 2ffcb1828490f51366ae19e29cbfe6c74f3332cb..43c710cf02d772dcdfda8e283ce6998a62c2e74b 100644 (file)
@@ -1,4 +1,4 @@
-@       86400   IN  SOA pdns-public-ns1.powerdns.com. peter\.van\.dijk.powerdns.com. 2026060801 10800 3600 604800 10800
+@       86400   IN  SOA pdns-public-ns1.powerdns.com. peter\.van\.dijk.powerdns.com. 2026062501 10800 3600 604800 10800
 @       3600    IN  NS  pdns-public-ns1.powerdns.com.
 @       3600    IN  NS  pdns-public-ns2.powerdns.com.
 
@@ -143,7 +143,8 @@ auth-4.9.11.security-status                             60 IN TXT "3 Upgrade now
 auth-4.9.12.security-status                             60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
 auth-4.9.13.security-status                             60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
 auth-4.9.14.security-status                             60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html"
-auth-4.9.15.security-status                             60 IN TXT "1 OK"
+auth-4.9.15.security-status                             60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-4.9.16.security-status                             60 IN TXT "1 OK"
 auth-5.0.0-alpha1.security-status                       60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
 auth-5.0.0-beta1.security-status                        60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
 auth-5.0.0.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
@@ -151,11 +152,13 @@ auth-5.0.1.security-status                              60 IN TXT "3 Upgrade now
 auth-5.0.2.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
 auth-5.0.3.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
 auth-5.0.4.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html"
-auth-5.0.5.security-status                              60 IN TXT "1 OK"
+auth-5.0.5.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-5.0.6.security-status                              60 IN TXT "1 OK"
 auth-5.1.0-alpha1.security-status                       60 IN TXT "3 Superseded pre-release (known vulnerabilities)"
 auth-5.1.0-beta1.security-status                        60 IN TXT "3 Unsupported pre-release (known vulnerabilities)"
-auth-5.1.0.security-status                              60 IN TXT "1 OK"
-auth-5.1.1.security-status                              60 IN TXT "1 OK"
+auth-5.1.0.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-5.1.1.security-status                              60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-5.1.2.security-status                              60 IN TXT "1 OK"
 
 ; Auth Debian
 auth-3.4.1-2.debian.security-status                     60 IN TXT "3 Upgrade now, see https://docs.powerdns.com/authoritative/appendices/EOL.html"
diff --git a/docs/security-advisories/powerdns-advisory-2026-07.rst b/docs/security-advisories/powerdns-advisory-2026-07.rst
new file mode 100644 (file)
index 0000000..f9b93bf
--- /dev/null
@@ -0,0 +1,26 @@
+PowerDNS Security Advisory 2026-07: Insufficient input validation of internal web server
+========================================================================================
+
+- CVE: CVE-2026-42005
+- Date: 2026-06-25T00:00:00+01:00
+- Discovery date: 2026-04-25T00:00:00+01:00
+- Affects: PowerDNS Authoritative Server 3.4.0 up to and including 4.9.15, 5.0.5 and 5.1.1
+- Not affected: PowerDNS Authoritative Server 4.9.16, 5.0.6 and 5.1.2
+- Severity: Medium
+- Impact: Denial of service
+- Exploit: This problem can be triggered by a client sending crafted HTTP queries, but only if the internal webserver is enabled.
+- Risk of system compromise: None
+- Solution: Upgrade to patched version or do not enable the internal webserver
+- CWE: CWE-770
+- CVSS: 3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
+- Last affected: 4.9.15,5.0.5,5.1.1
+- First fixed: 4.9.16,5.0.6,5.1.2
+- Internal ID: 481
+
+An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
+
+`CVSS Score: 4.3 <https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1>`__
+
+The remedy is: upgrade to a patched version, or prevent network access to the internal webserver. In general for defense in-depth reasons we recommend making the internal web server only accessible to trusted clients.
+
+We would like to thank ilya rozentsvaig for bringing this issue to our attention.