PT-2025-36935 · Cncf+1 · Coredns+1

Thevilledev

·

Published

2025-09-09

·

Updated

2026-05-21

·

CVE-2025-58063

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: CoreDNS versions 1.2.0 through 1.12.3
Description: CoreDNS, a DNS server that chains plugins, contains a TTL confusion vulnerability within the etcd plugin. This flaw arises from the incorrect use of lease IDs as TTL values, potentially enabling DNS cache pinning attacks. Specifically, the TTL() function in plugin/etcd/etcd.go casts etcd lease IDs (64-bit integers) to uint32, resulting in excessively large TTLs when the lease ID is large. This allows attackers to pin DNS cache entries for extended periods, leading to a denial of service for DNS resolution of affected services. An attacker with etcd write access can exploit this by writing or updating a key with any lease, causing downstream resolvers and clients to cache answers for years.
Recommendations: CoreDNS versions prior to 1.12.4 are affected. Update to CoreDNS version 1.12.4 or later to resolve this issue.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

AZL-67097
AZL-67101
BDU:2025-13303
CLEANSTART-2026-VJ54611
CVE-2025-58063
ECHO-E94F-2815-5E57
GHSA-93MF-426M-G6X9
GO-2025-3942
OPENSUSE-SU-2025:15561-1
OPENSUSE-SU-2025:15564-1
OPENSUSE-SU-2026:20099-1
SUSE-SU-2025:03289-1

Affected Products

Coredns
Red Os