Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:01792-1

Опубликовано: 02 июн. 2025
Источник: suse-cvrf

Описание

Security update for dnsdist

This update for dnsdist fixes the following issues:

  • CVE-2025-30193: stack exhaustion when processing too many queries on incoming TCP connections leads to a denial-of-service (bsc#1243378).

Список пакетов

SUSE Enterprise Storage 7.1
dnsdist-1.8.0-150100.3.8.1
SUSE Linux Enterprise Server 15 SP3-LTSS
dnsdist-1.8.0-150100.3.8.1

Описание

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.10 version. A workaround is to restrict the maximum number of queries on incoming TCP connections to a safe value, like 50, via the setMaxTCPQueriesPerConnection setting. We would like to thank Renaud Allard for bringing this issue to our attention.


Затронутые продукты
SUSE Enterprise Storage 7.1:dnsdist-1.8.0-150100.3.8.1
SUSE Linux Enterprise Server 15 SP3-LTSS:dnsdist-1.8.0-150100.3.8.1

Ссылки