Update designate to patched images cve-2026-71193

Designate cross-tenant DNS zone overlap and mDNS DoS

Tore Anderson (Redpill Linpro AS) reported a vulnerability in OpenStack Designate zone scheduling. An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected.

Omer Schwartz (Red Hat) discovered a related vulnerability in the Designate mDNS handler during triage. The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP.

Security Advisory: https://yaook.cloud/security-advisories-cve-2026-71193-71194/

Merge request reports

Loading
Loading