Vulnerability record · CVE-2021-36754 · published 30 July 2021
CVE-2021-36754: PowerDNS Authoritative Server crash via QTYPE 65535 query
Powerdns · Authoritative Server
PowerDNS Authoritative Server 4.5.0 before 4.5.1 crashes when it receives a query with QTYPE 65535, which triggers an out-of-bounds exception. The flaw is a remotely reachable denial of service in a core DNS component, so any exposed authoritative server running the affected version is at risk of going down.
Description
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated crash of a DNS server with a high EPSS score and no listed KEV entry, making it a serious availability risk for exposed instances.
What it is
PowerDNS Authoritative Server 4.5.0 before 4.5.1 crashes when it receives a query with QTYPE 65535, which triggers an out-of-bounds exception. The flaw is a remotely reachable denial of service in a core DNS component, so any exposed authoritative server running the affected version is at risk of going down.
Impact
An unauthenticated attacker can crash the PowerDNS process, causing loss of DNS resolution for zones served by that instance until it is restarted. No data confidentiality or integrity impact is described; the effect is availability only.
Attack surface
The vulnerability is reached over the network by sending a crafted DNS query with QTYPE 65535 to the authoritative server. No authentication or user interaction is required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
The record does not state that exploitation has been observed; CISA KEV does not list it, while EPSS is high at 0.64857 (99.2nd percentile), indicating elevated predicted likelihood. References are vendor advisories and a mailing list post, with no public exploit tag.
What to do
- Upgrade PowerDNS Authoritative Server to 4.5.1 or later, which the vendor advisory identifies as the fixed release.
- If immediate upgrade is not possible, restrict DNS query access to trusted resolvers and networks rather than exposing the server broadly.
- Monitor the PowerDNS process for unexpected restarts or crashes and alert on them.
- Review exposure of authoritative servers on the public internet and remove unnecessary reachability.
Detection
- Alert on PowerDNS process termination or restart events correlated with inbound DNS traffic.
- Search DNS query logs for QTYPE 65535 requests, which are abnormal for normal resolution traffic.
- Baseline and monitor for spikes in malformed or unusual QTYPE queries against authoritative servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/07/26/2 | Mailing ListThird Party Advisory |
| https://doc.powerdns.com/authoritative/security-advisories/index.html | Vendor Advisory |
| https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2021-01.html | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/07/26/2 | Mailing ListThird Party Advisory |
| https://doc.powerdns.com/authoritative/security-advisories/index.html | Vendor Advisory |
| https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2021-01.html | Vendor Advisory |
Track CVE-2021-36754 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36754), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.