CVE-2016-6172: Opensuse Leap

Medium severity, CVSS 6.8. EPSS: 3.8% chance of exploitation in the next 30 days.

PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.

Affected products

  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Powerdns Authoritative Server: up to and including 4.0.0

Published 2016-09-26. Last modified 2026-06-17.