=============================================================================OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling
=============================================================================
:Date: August 11, 2026
:CVE: CVE-2026-71193,
CVE-2026-71194
Affects
~~~~~~~
- Designate: >=1.0.0 <20.0.2, ==21.0.0, ==22.0.0
Description
~~~~~~~~~~~
Tore Anderson of Redpill Linpro AS reported that OpenStack Designate
does not enforce cross-pool zone ownership checks when scheduling a zone
to a non-default pool via the attribute filter. A tenant can create a
sub-zone, super-zone, or duplicate of another tenant's zone by targeting
a different pool, enabling DNS hijack or denial of service.
Independently, Omer Schwartz of Red Hat identified that the mDNS handler
performs pool-blind record lookups, causing a deterministic denial of
service when colliding zones exist across pools. All deployments using
multiple Designate pools are affected.
Patches ~~~~~~~ - https://review.opendev.org/1000475 (2025.1/epoxy) - https://review.opendev.org/1000474 (2025.2/flamingo) - https://review.opendev.org/1000473 (2026.1/gazpacho) - https://review.opendev.org/1000471 (2026.2/hibiscus (development)) Credits ~~~~~~~ - Tore Anderson from Redpill Linpro AS - Omer Schwartz from Red Hat References ~~~~~~~~~~ - https://launchpad.net/bugs/2160533 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71193 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71194 Notes ~~~~~ - The stable branch patches depend on two prerequisite backports (mDNS split-horizon pool scoping, Change 998005/998006 and their stable equivalents) that were merged before disclosure. Operators applying the fix to releases older than the next point release should ensure those prerequisite commits are present. - Operators should audit existing zones for cross-tenant collisions that may have been created before the fix. A detection tool will be proposed as a separate public patch. -- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html
OpenPGP_0x0638DAD3B82C3988.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
