<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:33:25 +0000</lastBuildDate>
    <item>
      <title>CVE-2019-19331</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2019-19331</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CZ.NIC knot-resolver&lt;/p&gt;
&lt;p&gt;knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CZ.NIC knot-resolver&lt;/p&gt;
&lt;p&gt;knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2019-19331</guid>
    </item>
    <item>
      <title>USN-7047-1 — knot-resolver vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7047-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: knot-resolver&lt;/p&gt;
&lt;p&gt;Vladimír Čunát discovered that Knot Resolver incorrectly handled input
during DNSSEC validation. A remote attacker could possibly use this issue
to bypass certain validations. (CVE-2019-10190)&lt;/p&gt;
&lt;p&gt;Vladimír Čunát discovered that Knot Resolver incorrectly handled input
during DNSSEC validation. A remote attacker could possibly use this issue
to downgrade DNSSEC-secure domains to a DNSSEC-insecure state, resulting 
in a domain hijacking attack. (CVE-2019-10191)&lt;/p&gt;
&lt;p&gt;Vladimír Čunát discovered that Knot Resolver incorrectly handled certain 
DNS replies with many resource records. An attacker could possibly use 
this issue to consume system resources, resulting in a denial of service.
(CVE-2019-19331)&lt;/p&gt;
&lt;p&gt;Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Knot
Resolver incorrectly handled certain queries. A remote attacker could 
use this issue to perform an amplification attack directed at a target.
(CVE-2020-12667)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: knot-resolver&lt;/p&gt;
&lt;p&gt;Vladimír Čunát discovered that Knot Resolver incorrectly handled input
during DNSSEC validation. A remote attacker could possibly use this issue
to bypass certain validations. (CVE-2019-10190)&lt;/p&gt;
&lt;p&gt;Vladimír Čunát discovered that Knot Resolver incorrectly handled input
during DNSSEC validation. A remote attacker could possibly use this issue
to downgrade DNSSEC-secure domains to a DNSSEC-insecure state, resulting 
in a domain hijacking attack. (CVE-2019-10191)&lt;/p&gt;
&lt;p&gt;Vladimír Čunát discovered that Knot Resolver incorrectly handled certain 
DNS replies with many resource records. An attacker could possibly use 
this issue to consume system resources, resulting in a denial of service.
(CVE-2019-19331)&lt;/p&gt;
&lt;p&gt;Lior Shafir, Yehuda Afek, and Anat Bremler-Barr discovered that Knot
Resolver incorrectly handled certain queries. A remote attacker could 
use this issue to perform an amplification attack directed at a target.
(CVE-2020-12667)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7047-1</guid>
    </item>
  </channel>
</rss>
