CVE-2026-64193
N/A
N/A
Summary
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR.
Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:"<command>"} in EXTRA-TEXT.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLNETLABS | Net::DNS | 0 <= 1.55 | affected |
Weaknesses
- CWE-95: CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
ADP Enrichment
CVE Program Container
Additional References
References
- https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56
- https://rt.cpan.org/Ticket/Display.html?id=179945
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.