Описание
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
A flaw was found in Twisted, specifically within the twisted.names module. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted TCP DNS packet containing deeply chained compression pointers. This can lead to resource exhaustion, causing the single-threaded Twisted reactor to hang and effectively freezing the server, resulting in a Denial of Service (DoS).
Отчет
A flaw was found in the twisted.names DNS module of the Python Twisted framework. A remote unauthenticated attacker can send a single crafted TCP DNS packet containing deeply chained compression pointers and thousands of question records to hang the single-threaded Twisted reactor, effectively freezing the server. The visited set that prevents infinite loops has no limit on total pointer dereferences and is reset per question record, allowing resource exhaustion. Red Hat Ansible Automation Platform components (automation-controller, EDA controller, Lightspeed) bundle python-twisted but use it via Daphne as an ASGI server. These components do not import or execute twisted.names, so the vulnerable DNS decompression code is never reached. Red Hat Enterprise Linux 6 ships python-twisted but is out of support scope (ELS does not cover python-twisted).
Меры по смягчению последствий
There is no mitigation for this issue. Applications using twisted.names for DNS resolution or as a DNS server should update to a fixed version of Twisted when available. Upgrade to a patched version (>= 26.4.0rc2).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/controller-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/eda-controller-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | automation-controller | Not affected | ||
| Red Hat Ansible Automation Platform 2 | python-twisted | Not affected | ||
| Red Hat Enterprise Linux 6 | python-twisted | Out of support scope | ||
| Red Hat Hardened Images | python-jsonschema | Not affected | ||
| Red Hat OpenStack Platform 16.2 | python-twisted | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Twisted is an event-based framework for internet applications, support ...
7.5 High
CVSS3