CVE-2026-93657
Publication date 21 September 2026
Last updated 21 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rust-hickory-resolver | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy | Not in release |
Severity score breakdown
CVSS version:
Base score
8.7 · High
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Base score
7.5 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-93657
- https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6
- https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238
- https://github.com/hickory-dns/hickory-dns
- https://github.com/hickory-dns/hickory-dns/pull/3871
- https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2
- https://www.vulncheck.com/advisories/hickory-resolver-before-0.26.2-dnssec-validation-bypass