netavark has incorrect error handling for malformed tcp packets
Moderate severity
GitHub Reviewed
Published
Apr 7, 2026
in
containers/aardvark-dns
•
Updated Apr 8, 2026
Description
Published to the GitHub Advisory Database
Apr 7, 2026
Reviewed
Apr 7, 2026
Published by the National Vulnerability Database
Apr 7, 2026
Last updated
Apr 8, 2026
Impact
A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU.
Patches
containers/aardvark-dns@3b49ea7
Workarounds
None
Credits
Thanks to @dkane01 for reporting this
References