{"id":"AZL-92441","summary":"CVE-2026-62299 affecting package coredns for versions less than 1.11.4-20","details":"CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, call res.IsEdns0() and immediately dereference the returned *dns.OPT without a nil check when a downstream plugin returns a response with no OPT record. A remote, unauthenticated client can send a single ordinary DNS query matching a rewrite edns0 \u003clocal|nsid|subnet\u003e \u003cset|append|replace\u003e ... revert rule, causing ResponseReverter in plugin/rewrite/reverter.go to panic, return SERVFAIL, and degrade availability, or crash the CoreDNS process if the debug directive disables recovery. This issue is fixed in version 1.14.5.","modified":"2026-08-31T05:26:27Z","published":"2026-07-16T20:16:46Z","upstream":["CVE-2026-62299"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62299"}],"affected":[{"package":{"name":"coredns","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/coredns"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.4-20"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92441.json"}}],"schema_version":"1.9.0"}