Security: samboy/MaraDNS
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
TCP idle-timeout bypass in tcp_send_wanted() permanently exhausts TCP connection slots — remote unauthenticated DoS (TCP sibling-gap of CVE-2026-40719)GHSA-8gcw-cm42-pcqq published
Jun 11, 2026 by samboyModerate -
Deadwood (MaraDNS 3.5.0036) Applies Full Fixed-Interval Retry Period to Any Unresolvable Nameserver, Exhausting Upstream Connection Slots and Causing Resolver UnavailabilityGHSA-cfc6-vhrv-62cj published
Mar 21, 2026 by samboyLow -
QR=0 (Query) Packets Unconditionally Accepted as Valid Upstream Responses in Deadwood Recursive Resolver, Enabling Cache Poisoning and Negative Cache InjectionGHSA-4jxw-xjwg-c754 published
Mar 9, 2026 by samboyLow -
Integer Underflow Vulnerability in DNS Packet DecompressionGHSA-58m7-826v-9c3c published
May 3, 2023 by samboyHigh