CVE-2024-8418: Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service

Published Sep 4, 2024
·
Updated

A flaw was found in Aardvark-dns versions 1.12.0 and 1.12.1. They contain a denial of service vulnerability due to serial processing of TCP DNS queries. This flaw allows a malicious client to keep a TCP connection open indefinitely, causing other DNS queries to time out and resulting in a denial of service for all other containers using aardvark-dns.

Other sources

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.

NVD

The affected versions (1.12.0 and 1.12.1) of aardvark-dns introduced TCP support but processed DNS queries serially. This flaw can be exploited by a malicious client to maintain an open TCP connection indefinitely, resulting in a denial of service for other DNS queries.

Red Hat

Affected Software

3 affected componentsFixes available
containers aardvark-dns=1.12.0
containers aardvark-dns=1.12.1
rust/aardvark-dns>=1.12.0<1.12.2
1.12.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/aardvark-dns to a version that resolves this vulnerability.

    Fixed in 1.12.2

Event History

Sep 4, 2024
Data Sourced
via Red Hat·10:57 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-8418?

CVE-2024-8418 has a severity rating that indicates a moderate risk primarily due to its denial of service nature.

2

How do I fix CVE-2024-8418?

To fix CVE-2024-8418, you should upgrade Aardvark-dns to version 1.12.2 or later.

3

Which versions of Aardvark-dns are affected by CVE-2024-8418?

Aardvark-dns versions 1.12.0 and 1.12.1 are affected by CVE-2024-8418.

4

What type of vulnerability is CVE-2024-8418?

CVE-2024-8418 is categorized as a denial of service vulnerability.

5

Can CVE-2024-8418 cause service interruptions?

Yes, CVE-2024-8418 can lead to service interruptions by causing other DNS queries to time out.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203