What is CVE-2026-39155?
CVE-2026-39155 is a vulnerability in the 'mod-onlinesign' module of Knot DNS versions before 3.4.10 and 3.5.x before 3.5.4, where the next NSEC owner name can be incorrectly computed. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize incorrect data. Affected systems should be updated to the patched versions.
Azərbaycanca: CVE-2026-39155, Knot DNS-in 3.4.10-dan əvvəlki və 3.5.x-in 3.5.4-dən əvvəlki versiyalarında 'mod-onlinesign' modulunda zəiflikdir. Bu zəiflik növbəti NSEC sahib adının yanlış hesablanmasına səbəb olur, nəticədə həddindən artıq geniş autentifikasiya inkar intervalı yaranır və aqressiv neqativ keşləmə istifadə edən aşağı axın doğrulayıcı resolver-lər saxta məlumat sintez edə bilər. Təsirə məruz qalan sistemləri müvafiq versiyalara yeniləmək tövsiyə olunur.
FAQ2
Which module of Knot DNS is affected by CVE-2026-39155?
The vulnerability is in the 'mod-onlinesign' module.
How can CVE-2026-39155 impact downstream validating resolvers using aggressive negative caching?
The incorrectly computed next NSEC owner name can create an overly broad authenticated denial interval, allowing these resolvers to synthesize incorrect data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.