An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-25 13:16
Updated : 2026-06-25 15:59
NVD link : CVE-2026-40209
Mitre link : CVE-2026-40209
CVE.ORG link : CVE-2026-40209
JSON object : View
Products Affected
No product.
CWE
CWE-772
Missing Release of Resource after Effective Lifetime
