PT-2024-5912 · Unknown+4 · Aardvark-Dns+4
Published
2024-09-04
·
Updated
2025-05-15
·
CVE-2024-8418
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Aardvark-dns versions 1.12.0 through 1.12.1
Description
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.
Recommendations
For versions 1.12.0 and 1.12.1, consider disabling the TCP DNS query processing functionality until a patch is available to prevent exploitation.
As a temporary workaround, restrict access to the TCP DNS query endpoint to minimize the risk of exploitation.
Avoid using the TCP connection indefinitely in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Aardvark-Dns
Almalinux
Red Hat
Rocky Linux