Security Advisories (5)
CVE-2007-6341 (2008-02-08)

Allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response.

CVE-2007-3409 (2007-06-26)

Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.

CVE-2007-3377 (2007-06-25)

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

CVE-2026-64193 (2026-07-20)

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

CVE-2026-64194 (2026-07-20)

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to a potential Denial of Service. The guard `$link < $offset` prevents forward and circular chains, but still allows arbitrarily long backward chains. The per-offset cache (`$cache`) is populated at the start of each call and short-circuits only re-traverses of the same offset - the initial descent through a fresh chain still recurses at full depth. A crafted packet can chain two-byte compression pointers so that each one points two bytes earlier than the previous, producing a chain length of `offset / 2`. For the 14-bit pointer field (max offset 16383) this gives up to ~8191 recursive frames. For a TCP DNS message the limit is the 16-bit length field (~32767 frames). Perl's default C stack handles only a few thousand frames; beyond that the process receives SIGSEGV or similar, which is a denial-of-service for any application parsing untrusted DNS data. The vulnerability is triggered by `Net::DNS::Packet->new(\$wire)` i.e. any point where the library decodes a DNS message from the network.

NAME

Net::DNS - Perl interface to the DNS resolver

SYNOPSIS

use Net::DNS;

DESCRIPTION

Net::DNS is a collection of Perl modules that act as a Domain Name System (DNS) resolver. It allows the programmer to perform DNS queries that are beyond the capabilities of gethostbyname and gethostbyaddr.

The programmer should be somewhat familiar with the format of a DNS packet and its various sections. See RFC 1035 or DNS and BIND (Albitz & Liu) for details.

Resolver Objects

A resolver object is an instance of the Net::DNS::Resolver class. A program can have multiple resolver objects, each maintaining its own state information such as the nameservers to be queried, whether recursion is desired, etc.

Packet Objects

Net::DNS::Resolver queries return Net::DNS::Packet objects. Packet objects have five sections:

  • The header section, a Net::DNS::Header object.

  • The question section, a list of Net::DNS::Question objects.

  • The answer section, a list of Net::DNS::RR objects.

  • The authority section, a list of Net::DNS::RR objects.

  • The additional section, a list of Net::DNS::RR objects.

The Net::DNS::Update package is a front-end to Net::DNS::Packet for creating packet objects to be used in dynamic updates.

Header Objects

Net::DNS::Header objects represent the header section of a DNS packet.

Question Objects

Net::DNS::Question objects represent the question section of a DNS packet.

RR Objects

Net::DNS::RR is the base class for DNS resource record (RR) objects in the answer, authority, and additional sections of a DNS packet.

Don't assume that RR objects will be of the type you requested -- always check an RR object's type before calling any of its methods.

METHODS

See the manual pages listed above for other class-specific methods.

version

print Net::DNS->version, "\n";

Returns the version of Net::DNS.

mx

# Use a default resolver -- can't get an error string this way.
use Net::DNS;
my @mx = mx("example.com");

# Use your own resolver object.
use Net::DNS;
my $res = Net::DNS::Resolver->new;
my  @mx = mx($res, "example.com");

Returns a list of Net::DNS::RR::MX objects representing the MX records for the specified name; the list will be sorted by preference. Returns an empty list if the query failed or no MX records were found.

This method does not look up A records -- it only performs MX queries.

See "EXAMPLES" for a more complete example.

yxrrset

Use this method to add an "RRset exists" prerequisite to a dynamic update packet. There are two forms, value-independent and value-dependent:

# RRset exists (value-independent)
$packet->push("pre", yxrrset("host.example.com A"));

Meaning: At least one RR with the specified name and type must exist.

# RRset exists (value-dependent)
$packet->push("pre", yxrrset("host.example.com A 10.1.2.3"));

Meaning: At least one RR with the specified name and type must exist and must have matching data.

Returns a Net::DNS::RR object or undef if the object couldn't be created.

nxrrset

Use this method to add an "RRset does not exist" prerequisite to a dynamic update packet.

$packet->push("pre", nxrrset("host.example.com A"));

Meaning: No RRs with the specified name and type can exist.

Returns a Net::DNS::RR object or undef if the object couldn't be created.

yxdomain

Use this method to add a "name is in use" prerequisite to a dynamic update packet.

$packet->push("pre", yxdomain("host.example.com"));

Meaning: At least one RR with the specified name must exist.

Returns a Net::DNS::RR object or undef if the object couldn't be created.

nxdomain

Use this method to add a "name is not in use" prerequisite to a dynamic update packet.

$packet->push("pre", nxdomain("host.example.com"));

Meaning: No RR with the specified name can exist.

Returns a Net::DNS::RR object or undef if the object couldn't be created.

rr_add

Use this method to add RRs to a zone.

$packet->push("update", rr_add("host.example.com A 10.1.2.3"));

Meaning: Add this RR to the zone.

RR objects created by this method should be added to the "update" section of a dynamic update packet. The TTL defaults to 86400 seconds (24 hours) if not specified.

Returns a Net::DNS::RR object or undef if the object couldn't be created.

rr_del

Use this method to delete RRs from a zone. There are three forms: delete an RRset, delete all RRsets, and delete an RR.

# Delete an RRset.
$packet->push("update", rr_del("host.example.com A"));

Meaning: Delete all RRs having the specified name and type.

# Delete all RRsets.
$packet->push("update", rr_del("host.example.com"));

Meaning: Delete all RRs having the specified name.

# Delete an RR.
$packet->push("update", rr_del("host.example.com A 10.1.2.3"));

Meaning: Delete all RRs having the specified name, type, and data.

RR objects created by this method should be added to the "update" section of a dynamic update packet.

Returns a Net::DNS::RR object or undef if the object couldn't be created.

EXAMPLES

The following examples show how to use the Net::DNS modules. See the other manual pages and the demo scripts included with the source code for additional examples.

See the Net::DNS::Update manual page for an example of performing dynamic updates.

Look up a host's addresses.

use Net::DNS;
my $res   = Net::DNS::Resolver->new;
my $query = $res->search("host.example.com");

if ($query) {
    foreach my $rr ($query->answer) {
        next unless $rr->type eq "A";
        print $rr->address, "\n";
    }
}
else {
    print "query failed: ", $res->errorstring, "\n";
}

Find the nameservers for a domain.

use Net::DNS;
my $res   = Net::DNS::Resolver->new;
my $query = $res->query("example.com", "NS");

if ($query) {
    foreach $rr ($query->answer) {
        next unless $rr->type eq "NS";
        print $rr->nsdname, "\n";
    }
}
else {
    print "query failed: ", $res->errorstring, "\n";
}

Find the MX records for a domain.

use Net::DNS;
my $name = "example.com";
my $res  = Net::DNS::Resolver->new;
my @mx   = mx($res, $name);

if (@mx) {
    foreach $rr (@mx) {
        print $rr->preference, " ", $rr->exchange, "\n";
    }
}
else {
    print "can't find MX records for $name: ", $res->errorstring, "\n";
}
use Net::DNS;
my $res   = Net::DNS::Resolver->new;
my $query = $res->query("example.com", "SOA");

if ($query) {
    ($query->answer)[0]->print;
}
else {
    print "query failed: ", $res->errorstring, "\n";
}

Perform a zone transfer and print all the records.

use Net::DNS;
my $res  = Net::DNS::Resolver->new;
$res->nameservers("ns.example.com");

my @zone = $res->axfr("example.com");

foreach $rr (@zone) {
    $rr->print;
}

Perform a background query and do some other work while waiting for the answer.

use Net::DNS;
my $res    = Net::DNS::Resolver->new;
my $socket = $res->bgsend("host.example.com");

until ($res->bgisready($socket)) {
    # do some work here while waiting for the answer
    # ...and some more here
}

my $packet = $res->bgread($socket);
$packet->print;

Send a background query and use select to determine when the answer has arrived.

  use Net::DNS;
  use IO::Select;
  
  my $timeout = 5;
  my $res     = Net::DNS::Resolver->new;
  my $bgsock  = $res->bgsend("host.example.com");
  my $sel     = IO::Select->new($bgsock);
  
  # Add more sockets to $sel if desired.
  my @ready = $sel->can_read($timeout);
  if (@ready) {
      foreach my $sock (@ready) {
          if ($sock == $bgsock) {
              my $packet = $res->bgread($bgsock);
              $packet->print;
              $bgsock = undef;
          }
	      # Check for the other sockets.
	      $sel->remove($sock);
	      $sock = undef;
      }
  }
  else {
      print "timed out after $timeout seconds\n";
  }

BUGS

Net::DNS is slow. Real slow.

For other items to be fixed, please see the TODO file included with the source distribution.

COPYRIGHT

Copyright (c) 1997-2002 Michael Fuhr. All rights reserved. This program is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

AUTHOR INFORMATION

Net::DNS is currently maintained by a group, led by: Chris Reinhardt ctriv@net-dns.org

Net::DNS was created by: Michael Fuhr mike@fuhr.org

For more information see: http://www.net-dns.org/

SEE ALSO

perl(1), Net::DNS::Resolver, Net::DNS::Packet, Net::DNS::Update, Net::DNS::Header, Net::DNS::Question, Net::DNS::RR, RFC 1035, DNS and BIND by Paul Albitz & Cricket Liu