Debian Package Tracker
Register | Log in
Subscribe

knot-resolver

Choose email to subscribe with

general
  • source: knot-resolver (main)
  • version: 6.4.1-1
  • maintainer: knot-resolver packagers (DMD)
  • uploaders: Santiago Ruano Rincón [DMD] – Daniel Kahn Gillmor [DMD] – Jakub Ružička [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.3.1-1+deb11u1
  • oldstable: 5.6.0-1+deb12u1
  • old-sec: 5.6.0-1+deb12u1
  • stable: 5.7.5-1
  • testing: 6.4.0-1
  • unstable: 6.4.1-1
versioned links
  • 5.3.1-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.6.0-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.7.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • knot-resolver6 (1 bugs: 0, 1, 0, 0)
  • knot-resolver6-dev
  • knot-resolver6-module-dnstap
  • knot-resolver6-module-http
action needed
2 security issues in trixie high

There are 2 open security issues in trixie.

2 important issues:
  • CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
  • TEMP-0000000-040C76:
Created: 2026-07-24 Last update: 2026-07-25 08:00
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
  • TEMP-0000000-040C76:
Created: 2026-07-24 Last update: 2026-07-25 08:00
7 security issues in bullseye high

There are 7 open security issues in bullseye.

2 important issues:
  • CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
  • TEMP-0000000-040C76:
3 issues postponed or untriaged:
  • CVE-2022-40188: (needs triaging) Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
  • CVE-2023-26249: (needs triaging) Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.
  • CVE-2023-46317: (needs triaging) Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.
2 ignored issues:
  • CVE-2023-50387: Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
  • CVE-2023-50868: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Created: 2026-07-24 Last update: 2026-07-25 08:00
2 security issues in bookworm high

There are 2 open security issues in bookworm.

2 important issues:
  • CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
  • TEMP-0000000-040C76:
Created: 2026-07-24 Last update: 2026-07-25 08:00
lintian reports 4 warnings normal
Lintian reports 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-07-24 Last update: 2026-07-24 18:00
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2025-10-16 Last update: 2025-10-16 20:31
news
[rss feed]
  • [2026-07-23] Accepted knot-resolver 6.4.1-1 (source) into unstable (Simon Josefsson)
  • [2026-07-14] knot-resolver 6.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-03] Accepted knot-resolver 6.4.0-1 (source) into unstable (Simon Josefsson)
  • [2026-06-11] knot-resolver 6.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-08] Accepted knot-resolver 6.3.0-1 (source) into unstable (Santiago Ruano Rincón)
  • [2026-03-10] knot-resolver 6.2.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-06] Accepted knot-resolver 6.2.0-2 (source) into unstable (Santiago Ruano Rincón)
  • [2026-03-03] knot-resolver 6.1.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-02] Accepted knot-resolver 6.2.0-1 (source) into unstable (Santiago Ruano Rincón)
  • [2026-02-16] Accepted knot-resolver 6.1.0-2 (source) into unstable (Santiago Ruano Rincón)
  • [2026-02-09] knot-resolver REMOVED from testing (Debian testing watch)
  • [2026-01-23] Accepted knot-resolver 6.1.0-1 (source) into unstable (Santiago Ruano Rincón)
  • [2025-12-08] knot-resolver 6.0.17-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-02] Accepted knot-resolver 6.0.17-1 (source) into unstable (Jakub Ružička)
  • [2025-10-30] knot-resolver 6.0.15-4 MIGRATED to testing (Debian testing watch)
  • [2025-10-25] knot-resolver 6.0.15-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-24] Accepted knot-resolver 6.0.15-4 (source) into unstable (Jakub Ružička)
  • [2025-10-13] Accepted knot-resolver 6.0.15-3 (source) into unstable (Jakub Ružička)
  • [2025-10-10] Accepted knot-resolver 6.0.15-2 (source) into unstable (Jakub Ružička)
  • [2025-07-18] Accepted knot-resolver 6.0.15-1 (source) into experimental (Jakub Ružička)
  • [2025-07-14] Accepted knot-resolver 6.0.14-1 (source) into experimental (Jakub Ružička)
  • [2025-05-29] Accepted knot-resolver 6.0.13-1 (source) into experimental (Jakub Ružička)
  • [2025-05-05] knot-resolver 5.7.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-25] Accepted knot-resolver 6.0.12-1 (source) into experimental (Jakub Ružička)
  • [2025-04-24] Accepted knot-resolver 5.7.5-1 (source) into unstable (Jakub Ružička)
  • [2025-01-20] Accepted knot-resolver 6.0.10-1 (source) into experimental (Jakub Ružička)
  • [2024-11-20] Accepted knot-resolver 6.0.9-1 (source amd64) into experimental (Debian FTP Masters) (signed by: Jakub Ružička)
  • [2024-08-13] knot-resolver 5.7.4-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-11] Accepted knot-resolver 5.7.4-2 (source) into unstable (Chris Hofstaedtler) (signed by: Christian Hofstaedtler)
  • [2024-07-27] knot-resolver 5.7.4-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 4)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (100, -)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.4.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing