Junglewise Threat Intelligence

CVE-2026-35406: Containers Aardvark-dns infinite loop via malformed TCP DNS query

CVE-2026-35406 · Severity: high · CVSS 7.5 · Published 2026-04-07

Vendors: crates.io, Containers.

Executive brief

Aardvark-dns, a tool used to manage network addresses for software containers, contains a flaw that can be triggered by a specific type of network request. An attacker can send a malformed request that causes the server to consume 100% of the processor's power indefinitely. This results in a denial-of-service (DoS) condition, making the DNS service unavailable and potentially slowing down the entire host system.

Technical details

Aardvark-dns (versions 1.16.0 to 1.17.0) fails to correctly handle errors during TCP stream processing. Specifically, a truncated TCP DNS query followed immediately by a connection reset (RST) triggers an unrecoverable infinite error loop (CWE-835). This occurs because the server fails to abort the TCP stream upon encountering the malformed packet and instead retries the operation indefinitely, consuming 100% of the CPU. While some metrics suggest a local attack vector, the nature of DNS services often exposes this to the network. The issue is resolved in version 1.17.1 by ensuring the TCP stream is correctly terminated on error.

Affected products

  • containers aardvark-dns >= 1.16.0, < 1.17.1

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: patched: Fixed in version 1.17.1
  • 2026-04-07: advisory

References

Related threats