CVE-2026-35406: Aardvark-dns has incorrect error handling for malformed tcp packets
Impact
A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU.
Patches https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1
Workarounds None
Credits
Thanks to @dkane01 for reporting this
Other sources
Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rust/netavarkto a version that resolves this vulnerability.Fixed in 1.17.1 - Upgrade
Upgrade
aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.17.1Patch 3b49ea7b38bdea134b7f03256f2e13f44ce73bb1