securityonline.info 24 Jul 2026, 02:39 UTC

Heap overflow bug in Knot Resolver lets attackers run code

Heap overflow bug in Knot Resolver lets attackers run code
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Listed in KEV
Patch Patch Available

THE article discusses a critical vulnerability (CVE-2026-16232) in Knot Resolver, which is an open-source caching recursive resolver used by large ISPs. The vulnerability involves improper authentication and allows remote code execution (RCE) due to a heap overflow in the DNS-over-QUIC (DoQ) listener, requiring no authentication. The issue arises from incorrect size tracking during frame processing, allowing attackers to overwrite function pointers and gain control of the instruction pointer.

A proof-of-concept (PoC) exploit code is publicly available, although no confirmed exploitation has occurred in the wild. It is critical for users to upgrade to Knot Resolver version 6.4.1, released on July 22, 2026, to mitigate this risk. Furthermore, users should consider disabling the DoQ listener or restricting access to trusted clients in the meantime.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline