Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32934

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When the worker pool is full, CoreDNS still spawns a goroutine per accepted stream to wait for a worker token. Additionally, active workers block indefinitely in io.ReadFull() with no per-stream read deadline, allowing an attacker to pin all workers by sending a single byte so the read blocks waiting for the second byte of the DoQ length prefix. This enables an unauthenticated remote attacker to cause memory exhaustion and OOM-kill. This issue has been fixed in version 1.14.3. No known workarounds exist.

A flaw was found in CoreDNS, a DNS server that chains plugins. The DNS-over-QUIC (DoQ) server is vulnerable to unbounded resource growth. An unauthenticated remote attacker can exploit this by opening numerous QUIC streams and sending only one byte per stream, causing the server to spawn excessive goroutines and consume unbounded memory. This leads to memory exhaustion and a Denial of Service (DoS) condition, making the server unresponsive.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-agent-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-coredns-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-coredns-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2466863coredns: github.com/coredns/coredns: CoreDNS: Denial of Service due to unbounded resource growth in DNS-over-QUIC (DoQ) stream handling

EPSS

Процентиль: 38%
0.00469
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When the worker pool is full, CoreDNS still spawns a goroutine per accepted stream to wait for a worker token. Additionally, active workers block indefinitely in io.ReadFull() with no per-stream read deadline, allowing an attacker to pin all workers by sending a single byte so the read blocks waiting for the second byte of the DoQ length prefix. This enables an unauthenticated remote attacker to cause memory exhaustion and OOM-kill. This issue has been fixed in version 1.14.3. No known workarounds exist.

msrc
3 месяца назад

CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service

CVSS3: 7.5
debian
3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14 ...

CVSS3: 7.5
redos
10 дней назад

Уязвимость coredns

CVSS3: 7.5
github
3 месяца назад

CoreDNS' DoQ worker pool does not bound stream backlog

EPSS

Процентиль: 38%
0.00469
Низкий

5.9 Medium

CVSS3