HIGH7.5
GHSA-hfpq-x728-986j
netavark has incorrect error handling for malformed tcp packets
Details
### Impact
A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU.
### Patches https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1
### Workarounds None
### Credits
Thanks to @dkane01 for reporting this
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/netavark
Introduced in:
1.16.0Fixed in: 1.17.1Upgrade netavark to 1.17.1 or newer (ecosystem crates.io).
References
- https://github.com/containers/aardvark-dns/security/advisories/GHSA-hfpq-x728-986j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-35406[ADVISORY]
- https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1[WEB]
- https://github.com/containers/aardvark-dns[PACKAGE]
- https://github.com/containers/aardvark-dns/releases/tag/v1.17.1[WEB]