A remotely triggerable heap buffer overflow in Knot Resolver 6.3.0 allows unauthenticated remote code execution through the kresd DNS-over-QUIC listener. The flaw stems from incorrect size tracking during inbound QUIC STREAM frame reassembly, causing a later memcpy() to write past an allocated heap buffer. Public reporting said a single QUIC connection carrying six crafted STREAM frames can produce a controlled out-of-bounds write and, with heap grooming, overwrite a libgnutls cleanup handler to seize control of a function pointer and argument. Researchers classified the issue as CWE-787 and demonstrated end-to-end RCE in a Debian 12 lab environment with ASLR disabled; failed attempts can also crash worker processes and cause denial of service.
CZ.NIC fixed the vulnerability in Knot Resolver 6.4.1, and full technical details plus working proof-of-concept exploit code were disclosed publicly shortly after the patch release. No in-the-wild exploitation has been confirmed, but the exposure is significant because Knot Resolver is deployed by major ISPs and handles untrusted network traffic, raising the risk of resolver compromise and forged DNS responses for downstream users. Organizations are being urged to upgrade to 6.4.1 immediately; if patching cannot be completed at once, defenders should disable DNS-over-QUIC, restrict access to the DoQ service, and monitor for repeated kresd worker crashes that could indicate exploitation attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CZ.NIC released Knot Resolver 6.4.1 to fix the remotely triggerable DNS-over-QUIC heap out-of-bounds write in version 6.3.0. The coordinated disclosure write-up identifies 2026-07-22 as the fix release date.
A researcher publicly released full technical details and working proof-of-concept exploit code for the Knot Resolver DNS-over-QUIC vulnerability. The write-up described how crafted QUIC STREAM frames could achieve end-to-end RCE in a lab environment.
CZ.NIC fixed the DNS-over-QUIC heap out-of-bounds write in Knot Resolver by releasing version 6.4.1. The vulnerable version identified in the references is Knot Resolver 6.3.0.
A remotely triggerable heap buffer overflow in Knot Resolver 6.3.0's DNS-over-QUIC receive path was reported to CZ.NIC. The flaw could lead to unauthenticated remote code execution or, at minimum, worker-process crashes causing denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcegithub.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.