Vulnerability record · CVE-2019-19331 · published 16 December 2019
CVE-2019-19331: Nic knot resolver improper resource shutdown vulnerability
Nic · Knot Resolver
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).
Description
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19331 | ExploitIssue TrackingPatch |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00017.html | |
| https://www.knot-resolver.cz/2019-12-04-knot-resolver-4.3.0.html | Release NotesVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19331 | ExploitIssue TrackingPatch |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00017.html | |
| https://www.knot-resolver.cz/2019-12-04-knot-resolver-4.3.0.html | Release NotesVendor Advisory |
Track CVE-2019-19331 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-19331), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.