git: 7f52e258f9fb - main - security/vuxml: Document dns/{ldns,py-ldns} vulnerability

From: Yusuf Yaman <nxjoseph_at_FreeBSD.org>
Date: Wed, 24 Jun 2026 10:38:11 UTC
The branch main has been updated by nxjoseph:

URL: https://cgit.FreeBSD.org/ports/commit/?id=7f52e258f9fbf4db0fe809f5def2ec2b21c442a1

commit 7f52e258f9fbf4db0fe809f5def2ec2b21c442a1
Author:     Yusuf Yaman <nxjoseph@FreeBSD.org>
AuthorDate: 2026-06-23 15:40:06 +0000
Commit:     Yusuf Yaman <nxjoseph@FreeBSD.org>
CommitDate: 2026-06-24 10:38:03 +0000

    security/vuxml: Document dns/{ldns,py-ldns} vulnerability
    
    PR:             296232
    Approved by:    osa, vvd (Mentors, implicit)
    Security:       CVE-2026-10846
---
 security/vuxml/vuln/2026.xml | 35 +++++++++++++++++++++++++++++++++++
 1 file changed, 35 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 9566d57e65e2..bf9df7e4c2be 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,38 @@
+  <vuln vid="71a85f96-6f18-11f1-8569-3c7c3fba4204">
+    <topic>ldns -- CWE-346 Origin Validation Error</topic>
+    <affects>
+    <package>
+	<name>ldns</name>
+	<range><ge>1.2.0</ge><lt>1.9.1</lt></range>
+    </package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p><a href="https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt">https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt</a> reports:</p>
+	<blockquote cite="https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt">
+	  <p>NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used
+in applications as (stub) resolver over UDP, lacks matching the
+query destination address and port with the response source address
+and port.  Furthermore not the query ID, neither the question of
+the query is matched with that of the response.  This makes
+applications, that use ldns for (stub) resolver functionality over
+UDP, vulnerable for off-path poisoning attacks.  The drill tool,
+which is shipped with ldns, suffers from this vulnerability.</p>
+<p>We would like to thank Pablo Ruiz from <a href="https://www.codecome.ai/">codecome.ai</a> for finding and reporting
+this vulnerability.</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2026-10846</cvename>
+      <url>https://cveawg.mitre.org/api/cve/CVE-2026-10846</url>
+    </references>
+    <dates>
+      <discovery>2026-06-10</discovery>
+      <entry>2026-06-23</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="fe2e8bdc-ff48-4166-b285-59822c7cf473">
     <topic>podman -- files outside build context may be included via malicious Git repo or tar archive</topic>
     <affects>