Home / mailings [SECURITY] [DSA 6045-1] pdns-recursor security update
Posted on 29 October 2025
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6045-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
October 29, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : pdns-recursor
CVE ID : CVE-2025-59023 CVE-2025-59024
Two vulnerabiliites have been discovered in PDNS Recursor, a resolving
name server: Delegation information was insufficiently validated, which
could result in cache pollution.
These changes are too intrusive to be backported to the version of
the PDNS recursor in the oldstable distribution (bookworm). For
affected setups an update to Debian stable/trixie is recommended,
no further security updates for pdns-recursor in Bookworm will be issued.
For the stable distribution (trixie), these problems have been fixed in
version 5.2.6-0+deb13u1.
We recommend that you upgrade your pdns-recursor packages.
For the detailed security status of pdns-recursor please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pdns-recursor
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
