CVE-2026-66374 is a remote code execution vulnerability in Knot Resolver affecting versions before 6.4.1. The flaw is caused by a heap-based buffer overflow in the DNS-over-QUIC (DoQ) receive path. A remote attacker can trigger memory corruption by sending crafted network traffic to a vulnerable Knot Resolver instance that processes DoQ traffic, potentially leading to attacker-controlled code execution within the resolver process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a compact PoC exploit for a remotely reachable heap out-of-bounds write in Knot Resolver 6.3.0’s DNS-over-QUIC receive path, specifically kresd/daemon/quic_conn.c. Structure is minimal: README.md documents the vulnerability, exploitation strategy, environment, and usage; poc.py is the main exploit implementation; probe.gdb is a helper oracle for one-time address recovery on an identical ASLR-disabled build; .gitignore is incidental. The exploit is not part of a larger framework. The main capability is remote unauthenticated exploitation over QUIC/DoQ. The Python script uses aioquic to open QUIC connections and send a crafted sequence of six DoQ stream frames that manipulate the target’s per-connection input buffer across jemalloc size classes, culminating in an out-of-bounds write into an adjacent heap slot. The code supports three modes: probe (benign five-frame sequence to let gdb capture the deterministic pers_inbuf address), rip (demonstrates control of instruction pointer and first argument by crashing the target with attacker-chosen sentinel values), and exec (full code execution by overwriting a libgnutls cleanup handler so teardown dispatch calls system() on an attacker-controlled command string). The exploit includes lightweight heap grooming via multiple short-lived QUIC connections to improve placement of the adjacent target object. In exec mode, the default payload is a bash reverse shell to attacker-controlled lhost/lport. The script can operate in a fully remote mode when both slot+1 and system() addresses are supplied, or in a convenience local mode where it reads /proc/<pid>/maps and resolves the system symbol from the local libc path. The README explicitly states that ASLR bypass is out of scope and that the PoC assumes kernel.randomize_va_space=0; therefore this is best classified as OPERATIONAL rather than weaponized. It is a real exploit, not merely a detector, and it can produce either DoS/crash or code execution as the knot-resolver service user depending on mode and reliability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.