CVE-2019-10163: Opensuse Backports

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

Affected products

  • Opensuse Backports: version sle-15 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Powerdns Authoritative: from 4.0.0, before 4.0.8 (fixed in 4.0.8); from 4.1.0, before 4.1.9 (fixed in 4.1.9); version 4.1.0 only

Published 2019-07-30. Last modified 2026-06-17.