CVE-2026-66374
published 2026-07-25CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
PriorityP352high8.1CVSS 3.1
AVNACHPRNUINSCCLIHAL
EPSS
0.50%
41.2th percentile
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nic | knot_resolver | < 6.4.1 | 6.4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
nic Knot Resolver up to 6.4.0 DNS-over-QUIC buffer overflow
vuldb·2026-07-25·CVSS 8.1
CVE-2026-66374 [HIGH] nic Knot Resolver up to 6.4.0 DNS-over-QUIC buffer overflow
A vulnerability was found in nic Knot Resolver up to 6.4.0. It has been declared as critical. Affected by this issue is some unknown functionality of the component DNS-over-QUIC. Executing a manipulation can lead to buffer overflow.
This vulnerability is tracked as CVE-2026-66374. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
ghsa_unreviewed·2026-07-25
CVE-2026-66374 [HIGH] CWE-1284 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path [epel-all]
bugzilla·2026-08-21·CVSS 8.1
CVE-2026-66374 [HIGH] CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path [epel-all]
CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
Bugzilla
CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path [fedora-all]
bugzilla·2026-08-21·CVSS 8.1
CVE-2026-66374 [HIGH] CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path [fedora-all]
CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
Bugzilla
CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path
bugzilla·2026-07-25·CVSS 8.1
CVE-2026-66374 [HIGH] CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path
CVE-2026-66374 knot-resolver: Knot Resolver: Remote code execution via heap-based buffer overflow in DoQ receive path
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
2026-07-25
Published