PT-2024-5912 · Unknown+4 · Aardvark-Dns+4

Published

2024-09-04

·

Updated

2025-05-15

·

CVE-2024-8418

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Aardvark-dns versions 1.12.0 through 1.12.1
Description A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.
Recommendations For versions 1.12.0 and 1.12.1, consider disabling the TCP DNS query processing functionality until a patch is available to prevent exploitation. As a temporary workaround, restrict access to the TCP DNS query endpoint to minimize the risk of exploitation. Avoid using the TCP connection indefinitely in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2025:7094
ALT-PU-2024-12696
ALT-PU-2024-15836
BDU:2024-06718
CVE-2024-8418
GHSA-G5JH-57WM-P79M
INFSA-2025_7094
OPENSUSE-SU-2024:14319-1
RHSA-2025:7094
RHSA-2025_7094

Affected Products

Alt Linux
Aardvark-Dns
Almalinux
Red Hat
Rocky Linux