#1144145 CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling #1144145
- Package:
- src:designate
- Source:
- src:designate
- Submitter:
- Thomas Goirand
- Date:
- 2026-08-24 22:33:02 UTC
- Severity:
- normal
- Tags:
As per upstream announce at: https://security.openstack.org/ossa/OSSA-2026-034.html Date: August 11, 2026 CVE: CVE-2026-71193, CVE-2026-71194 Affects: Designate: >=1.0.0 <20.0.2, ==21.0.0, ==22.0.0 Description: Tore Anderson of Redpill Linpro AS reported that OpenStack Designate does not enforce cross-pool zone ownership checks when scheduling a zone to a non-default pool via the attribute filter. A tenant can create a sub-zone, super-zone, or duplicate of another tenant’s zone by targeting a different pool, enabling DNS hijack or denial of service. Independently, Omer Schwartz of Red Hat identified that the mDNS handler performs pool-blind record lookups, causing a deterministic denial of service when colliding zones exist across pools. All deployments using multiple Designate pools are affected. Patches: https://review.opendev.org/1000475 (2025.1/epoxy) https://review.opendev.org/1000474 (2025.2/flamingo) https://review.opendev.org/1000473 (2026.1/gazpacho) https://review.opendev.org/1000471 (2026.2/hibiscus (development)) Credits: Tore Anderson from Redpill Linpro AS Omer Schwartz from Red Hat References: https://launchpad.net/bugs/2160533 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71193 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71194 Notes: The stable branch patches depend on two prerequisite backports (mDNS split-horizon pool scoping, Change 998005/998006 and their stable equivalents) that were merged before disclosure. Operators applying the fix to releases older than the next point release should ensure those prerequisite commits are present. Operators should audit existing zones for cross-tenant collisions that may have been created before the fix. A detection tool will be proposed as a separate public patch.
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/2f4854026762fb948f493156f4745ace443e0eef ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/1ab170e3c8639497975a7d36632656f809a5cf6e ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/e65ee8a3fa4c3f828f6f8755884d9108441b8641 ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/2a3b7f648e9522fce52457ad0444071df3e7c43e ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/83fdd24651cfb5c693b97b2b733baf36aa50e3a8 ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/b6330e264184508cf8df02e7f058ed0e3df42282 ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/82f5b54fd34cf58e6976815d2b09de00ef08e84c ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
Hello, Bug #1144145 in designate reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/designate/-/commit/3981821ff38b01dbe4d1a24d0cd36ee54ffbc404 ------------------------------------------------------------------------ * CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034: - An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected. - The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP. Applied upstream patches: - Require TSIG keys for zones in non-default pools - Fix mDNS record query pool scoping for split-horizon DNS - Fix cross-tenant/cross-pool zone ownership bypass (Closes: #1144145). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144145
We believe that the bug you reported is fixed in the latest version of
designate, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144145@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated designate package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 06 Aug 2026 10:01:30 +0200
Source: designate
Architecture: source
Version: 1:22.0.0-2
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144145
Changes:
designate (1:22.0.0-2) unstable; urgency=high
.
* CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034:
- An authenticated tenant can bypass zone ownership checks by scheduling a
zone to a different pool, creating overlapping zones that hijack or deny
service to another tenant's DNS records. Any user with the default
create_zone policy can exploit this when the AttributeFilter scheduler is
enabled. Only deployments using the AttributeFilter scheduler with
multiple pools are affected.
- The mDNS handler performs pool-blind record lookups that fail when
colliding zones exist across pools, causing deterministic DNS query
failures. The NOTIFY handler path is reachable via unauthenticated UDP.
Applied upstream patches:
- Require TSIG keys for zones in non-default pools
- Fix mDNS record query pool scoping for split-horizon DNS
- Fix cross-tenant/cross-pool zone ownership bypass
(Closes: #1144145).
Checksums-Sha1:
e545126cb7507e51fc08bc5c0aa1094f530a961a 4248 designate_22.0.0-2.dsc
088c255ce1aa0a2cb51d9647fd9abc3ad1b2b9d4 26624 designate_22.0.0-2.debian.tar.xz
7aed592dbefc0dc375eec413c61cccc07ab03993 21816 designate_22.0.0-2_amd64.buildinfo
Checksums-Sha256:
d9b73375bcc0988989892080e205b6c4f946e45f5eae0936c7699f851d381b36 4248 designate_22.0.0-2.dsc
f0e4c516f33e4c0ab6236758b754dc8b8960b6533ab4fb947a986786c06e755f 26624 designate_22.0.0-2.debian.tar.xz
424681d836e608b01057094ff907b1fecb89e45172c2eb40fea6f6c9c5780cee 21816 designate_22.0.0-2_amd64.buildinfo
Files:
13b36456a71ec3b65d649da5899a7002 4248 net optional designate_22.0.0-2.dsc
2035755bd533c143bd58a6bb265b0e52 26624 net optional designate_22.0.0-2.debian.tar.xz
b68bfa642150c84d0fb8220e34d1b9ea 21816 net optional designate_22.0.0-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmp8bFMACgkQ1BatFaxr
Q/79Xg/+MMY9EodXPilff+gqzMuWFMejwGoMkn4eVzPXU1g/ZOlD5GYzwf97rQyn
j9RTz5kwy4k56X6Nenm5CKibEhH3DhrPqxhlFwZguFMjOKk1RCQvjxT5hn/LeJdX
zi28guHbgaYRu4WQNP3smtsFk0dIp7SBbqr7i2+V6GrRxLGVG3P6IfE8JdWHxwmc
n6/kK/aFO2jkgldvb4GMpJWFSFTD3bVmvdm5kab5OzkihiyAk9fpkHJHOdcmDzV3
vvVHKZ0ejMBpUii0mXp4tjgJs7ogcwbfkClh23dF2a5dG4lqFDTVcFUJF6klRDAd
GOehORDhgqvgton4vnIc0sM6D7nvwBatquOThWl5OE6gPlHm+bdp+5Hk6aS91rsi
XRBcIv/vgltcAgIRUJBYWWXox/XnJTtGkSZuafHLaCJOxK/iBf5d6zKAyuBE49ZH
5UWszi1jDC6mMdlTnvvBf5Tp8BOVbOUUQxbYUMo+CV0trwhsth/TeKVEJFz53OUp
oqHhC/pgq7eYYidnRkXTUKy6msGQ1D0x37ltbN5iWYF1hEPpIg48dpT+LzWrytSv
z/AiUD/Hzci0TMmtECq9eeBZqWDxbwbWMSEhqlFse0scu3elKgKTthBEFjs1jIas
k4CDFx89TF3sWxBciJEgUBX7uiOPH3zQSuSCfxh+3g/EUI9sPyw=
=/4tG
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
designate, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144145@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated designate package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 06 Aug 2026 10:25:23 +0200
Source: designate
Architecture: source
Version: 1:20.0.0-2+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144145
Changes:
designate (1:20.0.0-2+deb13u1) trixie-security; urgency=medium
.
* CVE-2026-71193, CVE-2026-71194 / OSSA-2026-034:
- An authenticated tenant can bypass zone ownership checks by scheduling a
zone to a different pool, creating overlapping zones that hijack or deny
service to another tenant's DNS records. Any user with the default
create_zone policy can exploit this when the AttributeFilter scheduler is
enabled. Only deployments using the AttributeFilter scheduler with
multiple pools are affected.
- The mDNS handler performs pool-blind record lookups that fail when
colliding zones exist across pools, causing deterministic DNS query
failures. The NOTIFY handler path is reachable via unauthenticated UDP.
Applied upstream patches:
- Require TSIG keys for zones in non-default pools
- Fix mDNS record query pool scoping for split-horizon DNS
- Fix cross-tenant/cross-pool zone ownership bypass
(Closes: #1144145).
Checksums-Sha1:
9600252d6b8c34dd885f28de0c52dc76530a6ed5 4337 designate_20.0.0-2+deb13u1.dsc
2b6fd38f47f475cd9859ad72aea0c69641c58681 738480 designate_20.0.0.orig.tar.xz
412dac3864a842a1977403c994ff9230f876d838 26400 designate_20.0.0-2+deb13u1.debian.tar.xz
9867748b282616dd4582d8ce3315318e14f88ace 22467 designate_20.0.0-2+deb13u1_amd64.buildinfo
Checksums-Sha256:
ad52c9d0f53502990025b3b939bbe46cae854e8678902ab75e599a3a3fc44100 4337 designate_20.0.0-2+deb13u1.dsc
c63c1c95728b1cc258b00f8885e5a85ef170f6fd5a2e71c7be6735ae556c385a 738480 designate_20.0.0.orig.tar.xz
9957e940feb74976c78bf9c49bcb07aa5944d978051d03a1cf17c1c13c79e250 26400 designate_20.0.0-2+deb13u1.debian.tar.xz
1f447c470f23006cddd32e2021f1cef69c04f27a900e2918ceba322bae611628 22467 designate_20.0.0-2+deb13u1_amd64.buildinfo
Files:
f39c8f39533eb81224e23f65d18ed6b2 4337 net optional designate_20.0.0-2+deb13u1.dsc
b694063b70a4a1f770fd56fbd3a3ab34 738480 net optional designate_20.0.0.orig.tar.xz
bdfda1e13304bc974868fac699fdd9d9 26400 net optional designate_20.0.0-2+deb13u1.debian.tar.xz
c0934ae5185cae297414e6443bb8142e 22467 net optional designate_20.0.0-2+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqEgugACgkQ1BatFaxr
Q/6o/A/+JVxSEDOOujYw4Uw1hOKUW1cJ1+zEDMZyDC0mzEv8h1o3u/wMC/RbV4Qx
lyP7wMTlRSNcgUMayh4LeTfYZxW/GkgLIIOXv3nQLe7A9h51G+OR3rbwW8hje+60
vsRoxbj5fGIrN3PvlIM734sQ9AibOQeohhJ50sFOv1wiTOCfTjzt/IJ6npssuib7
bf6XdbZruhG/LuJoV4oUVF1TTc4hiVcTrGS1ld7g4ANw0A1THbrAkC8nZprWTEx/
4zl8EE+ruirlBNFl2rkA30qulKBLd7HHZKiwYCTeT7dpsrPYN10QoIzO3k245uW+
JH9bsNT/4cx5ZXZQKv8znIytWZDF+EVqgas9x8tA/oP6IfBBEhSDKCIUYBbECcdb
pYwx5ZBjyzKp4fHSfLjmpaNFdFcaVY7djZR/jLlqrY57gh7omyZf+Ntl8nMbGWoG
SAV86DZ58GfxMHw4CYsj8AHlgr+AkvmeKpL9h5egd2uqTHtDnnw35iMkobDsFxst
m/JwG0kY1ha8iFeGbKMSgwFo67rdO7dzxW8uUzKLcKKD++3M0Os3Dq01CJw4p6d4
GxFLphhXKK77WagVmGjINfKldX1LTv5wFT+1YVa/snfRbVp96MJqYS7ZiZ4HLjRw
qMyU5AdY042Qt0DCZQtrFTuK4vgtlZmHCnYDiKQWkiH0+CCbggk=
=hlv3
-----END PGP SIGNATURE-----