From: Miod Vallat Date: Thu, 25 Jun 2026 06:04:49 +0000 (+0200) Subject: documentation and secpoll update for auth 4.9.16, 5.0.6 and 5.1.2 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=7067d11957e5cb72e995a772b2e777655e82a67e;p=thirdparty%2Fpdns.git documentation and secpoll update for auth 4.9.16, 5.0.6 and 5.1.2 Signed-off-by: Miod Vallat --- diff --git a/docs/changelog/4.9.rst b/docs/changelog/4.9.rst index 95cdb06b4b..4272ab41ba 100644 --- a/docs/changelog/4.9.rst +++ b/docs/changelog/4.9.rst @@ -1,6 +1,21 @@ Changelogs for 4.9.x ==================== +.. changelog:: + :version: 4.9.16 + :released: 25th of June 2026 + + This is release 4.9.16 of the Authoritative Server. + It contains a security fix only. + + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x. + + .. change:: + :tags: Bug Fixes + :pullreq: 17591 + + Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server + .. changelog:: :version: 4.9.15 :released: 20th of May 2026 diff --git a/docs/changelog/5.0.rst b/docs/changelog/5.0.rst index fb49065026..eddcd1fb02 100644 --- a/docs/changelog/5.0.rst +++ b/docs/changelog/5.0.rst @@ -1,6 +1,21 @@ Changelogs for 5.0.x ==================== +.. changelog:: + :version: 5.0.6 + :released: 25th of June 2026 + + This is release 5.0.6 of the Authoritative Server. + It contains a security fix only. + + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. + + .. change:: + :tags: Bug Fixes + :pullreq: 17590 + + Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server + .. changelog:: :version: 5.0.5 :released: 20th of May 2026 @@ -8,7 +23,7 @@ Changelogs for 5.0.x This is release 5.0.5 of the Authoritative Server. It contains bug fixes and security fixes. - Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x. + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. .. change:: :tags: Bug Fixes @@ -107,7 +122,7 @@ Changelogs for 5.0.x This is release 5.0.4 of the Authoritative Server. It contains security fixes only. - Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x. + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. .. change:: :tags: Bug Fixes diff --git a/docs/changelog/5.1.rst b/docs/changelog/5.1.rst index 4f326d8aba..1aeb057d3e 100644 --- a/docs/changelog/5.1.rst +++ b/docs/changelog/5.1.rst @@ -1,6 +1,21 @@ Changelogs for 5.1.x ==================== +.. changelog:: + :version: 5.1.2 + :released: 25th of June 2026 + + This is release 5.1.2 of the Authoritative Server. + It contains a security fix only. + + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x. + + .. change:: + :tags: Bug Fixes + :pullreq: 17589 + + Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server + .. changelog:: :version: 5.1.1 :released: 8th of June 2026 @@ -8,7 +23,7 @@ Changelogs for 5.1.x This is release 5.1.1 of the Authoritative Server. It contains an important bugfix for users of the LMDB backend. - Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x. .. change:: :tags: Bug Fixes @@ -23,7 +38,7 @@ Changelogs for 5.1.x This is release 5.1.0 of the Authoritative Server. It provides many small new features and improvements, as well as bug fixes. - Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x. .. change:: :tags: Improvements @@ -146,7 +161,7 @@ Changelogs for 5.1.x It provides many small new features and improvements, as well as bug fixes, including fixes for the PowerDNS Security Advisory 2026-05. - Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x. .. change:: :tags: New Features @@ -315,7 +330,7 @@ Changelogs for 5.1.x This is release 5.1.0-alpha1 of the Authoritative Server. It provides many small new features and improvements, as well as bug fixes. - Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x. + Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x. .. change:: :tags: New Features diff --git a/docs/secpoll.zone b/docs/secpoll.zone index 2ffcb18284..43c710cf02 100644 --- a/docs/secpoll.zone +++ b/docs/secpoll.zone @@ -1,4 +1,4 @@ -@ 86400 IN SOA pdns-public-ns1.powerdns.com. peter\.van\.dijk.powerdns.com. 2026060801 10800 3600 604800 10800 +@ 86400 IN SOA pdns-public-ns1.powerdns.com. peter\.van\.dijk.powerdns.com. 2026062501 10800 3600 604800 10800 @ 3600 IN NS pdns-public-ns1.powerdns.com. @ 3600 IN NS pdns-public-ns2.powerdns.com. @@ -143,7 +143,8 @@ auth-4.9.11.security-status 60 IN TXT "3 Upgrade now auth-4.9.12.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" auth-4.9.13.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" auth-4.9.14.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html" -auth-4.9.15.security-status 60 IN TXT "1 OK" +auth-4.9.15.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html" +auth-4.9.16.security-status 60 IN TXT "1 OK" auth-5.0.0-alpha1.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" auth-5.0.0-beta1.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" auth-5.0.0.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" @@ -151,11 +152,13 @@ auth-5.0.1.security-status 60 IN TXT "3 Upgrade now auth-5.0.2.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" auth-5.0.3.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html" auth-5.0.4.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html" -auth-5.0.5.security-status 60 IN TXT "1 OK" +auth-5.0.5.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html" +auth-5.0.6.security-status 60 IN TXT "1 OK" auth-5.1.0-alpha1.security-status 60 IN TXT "3 Superseded pre-release (known vulnerabilities)" auth-5.1.0-beta1.security-status 60 IN TXT "3 Unsupported pre-release (known vulnerabilities)" -auth-5.1.0.security-status 60 IN TXT "1 OK" -auth-5.1.1.security-status 60 IN TXT "1 OK" +auth-5.1.0.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html" +auth-5.1.1.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html" +auth-5.1.2.security-status 60 IN TXT "1 OK" ; Auth Debian auth-3.4.1-2.debian.security-status 60 IN TXT "3 Upgrade now, see https://docs.powerdns.com/authoritative/appendices/EOL.html" diff --git a/docs/security-advisories/powerdns-advisory-2026-07.rst b/docs/security-advisories/powerdns-advisory-2026-07.rst new file mode 100644 index 0000000000..f9b93bf21e --- /dev/null +++ b/docs/security-advisories/powerdns-advisory-2026-07.rst @@ -0,0 +1,26 @@ +PowerDNS Security Advisory 2026-07: Insufficient input validation of internal web server +======================================================================================== + +- CVE: CVE-2026-42005 +- Date: 2026-06-25T00:00:00+01:00 +- Discovery date: 2026-04-25T00:00:00+01:00 +- Affects: PowerDNS Authoritative Server 3.4.0 up to and including 4.9.15, 5.0.5 and 5.1.1 +- Not affected: PowerDNS Authoritative Server 4.9.16, 5.0.6 and 5.1.2 +- Severity: Medium +- Impact: Denial of service +- Exploit: This problem can be triggered by a client sending crafted HTTP queries, but only if the internal webserver is enabled. +- Risk of system compromise: None +- Solution: Upgrade to patched version or do not enable the internal webserver +- CWE: CWE-770 +- CVSS: 3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L +- Last affected: 4.9.15,5.0.5,5.1.1 +- First fixed: 4.9.16,5.0.6,5.1.2 +- Internal ID: 481 + +An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. + +`CVSS Score: 4.3 `__ + +The remedy is: upgrade to a patched version, or prevent network access to the internal webserver. In general for defense in-depth reasons we recommend making the internal web server only accessible to trusted clients. + +We would like to thank ilya rozentsvaig for bringing this issue to our attention.