Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33811

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

A flaw was found in the net package of Go (golang), specifically when using the LookupCNAME function with the cgo DNS resolver. A remote attacker could exploit this by providing a very long Canonical Name (CNAME) response. This can trigger a double-free of C memory, leading to a crash and a Denial of Service (DoS) for the affected application.

Отчет

This is an Important denial of service vulnerability in the Go net package, affecting applications configured to use the cgo DNS resolver. A remote attacker could trigger a double-free memory error by providing a very long CNAME response, leading to a crash of the vulnerable application and impacting service availability.

Меры по смягчению последствий

To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the cgo DNS resolver. This can be achieved by setting the GODEBUG environment variable to netdns=go. For example, to run a Go application with this mitigation: GODEBUG=netdns=go /path/to/your/go/application. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Compliance Operatorcompliance/openshift-compliance-operator-bundleAffected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9-operatorAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Not affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2467822net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME

EPSS

Процентиль: 53%
0.00813
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

CVSS3: 7.5
nvd
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

msrc
3 месяца назад

Crash when handling long CNAME response in net

CVSS3: 7.5
debian
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...

rocky
16 дней назад

Important: git-lfs security update

EPSS

Процентиль: 53%
0.00813
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-33811