Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35406

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.

A flaw was found in aardvark-dns where a specially crafted TCP DNS query followed by a connection reset can trigger an infinite error loop, leading to 100% CPU usage and a denial of service. As aardvark-dns is only accessible via internal Podman networks, this issue can be exploited by a local container with network access.

Меры по смягчению последствий

As a mitigation, avoid using aardvark-dns when container name resolution is not required by creating Podman networks with DNS disabled (e.g., podman network create --disable-dns). This prevents the vulnerable component from being used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8container-tools:rhel8/aardvark-dnsAffected
Red Hat Enterprise Linux 8container-tools:rhel8/containers-commonNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10aardvark-dnsFixedRHSA-2026:3678208.07.2026
Red Hat Enterprise Linux 9aardvark-dnsFixedRHSA-2026:3631807.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2456280aardvark-dns: Aardvark-dns: Denial of Service via truncated TCP DNS query and connection reset

EPSS

Процентиль: 30%
0.00383
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
4 месяца назад

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.

CVSS3: 6.2
nvd
4 месяца назад

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.

CVSS3: 6.2
debian
4 месяца назад

Aardvark-dns is an authoritative dns server for A/AAAA container recor ...

rocky
21 день назад

Moderate: aardvark-dns security update

rocky
23 дня назад

Moderate: aardvark-dns security update

EPSS

Процентиль: 30%
0.00383
Низкий

6.5 Medium

CVSS3