CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-8418: Containers/aardvark-dns: tcp query handling flaw in aardvark-dns leading to denial of service

Description

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.

Classification

CVE ID: CVE-2024-8418

Problem Types

Uncontrolled Resource Consumption

Affected Products

Vendor: , Red Hat

Product: , Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.49% (probability of being exploited)

EPSS Percentile: 64.49% (scored less or equal to compared to others)

EPSS Date: 2025-06-11 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: true

References

https://nvd.nist.gov/vuln/detail/CVE-2024-8418
https://access.redhat.com/errata/RHSA-2025:7094
https://access.redhat.com/security/cve/CVE-2024-8418
https://bugzilla.redhat.com/show_bug.cgi?id=2309683
https://github.com/containers/aardvark-dns/issues/500
https://github.com/containers/aardvark-dns/pull/503

Timeline