GHSA-5j98-2g5x-46v6HighCVSS 7.5Disclosed before NVD
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
📋 Description
When calling Resolver::lookup() or Resolver::lookup_ip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.
🎯 Affected products1
- rust/hickory-resolver:< 0.26.2
🔗 References (5)
- https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6
- https://github.com/hickory-dns/hickory-dns/pull/3871
- https://github.com/hickory-dns/hickory-dns/commit/92f93c0b889f6a292bc943304d88c4c6561fe1b9
- https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2
- https://github.com/advisories/GHSA-5j98-2g5x-46v6