Executive brief
Aardvark-dns, a tool used to manage network addresses for software containers, contains a flaw that can be triggered by a specific type of network request. An attacker can send a malformed request that causes the server to consume 100% of the processor's power indefinitely. This results in a denial-of-service (DoS) condition, making the DNS service unavailable and potentially slowing down the entire host system.
Technical details
Aardvark-dns (versions 1.16.0 to 1.17.0) fails to correctly handle errors during TCP stream processing. Specifically, a truncated TCP DNS query followed immediately by a connection reset (RST) triggers an unrecoverable infinite error loop (CWE-835). This occurs because the server fails to abort the TCP stream upon encountering the malformed packet and instead retries the operation indefinitely, consuming 100% of the CPU. While some metrics suggest a local attack vector, the nature of DNS services often exposes this to the network. The issue is resolved in version 1.17.1 by ensuring the TCP stream is correctly terminated on error.
Affected products
- containers aardvark-dns >= 1.16.0, < 1.17.1
Timeline
- 2026-04-07: disclosed
- 2026-04-07: patched: Fixed in version 1.17.1
- 2026-04-07: advisory