MEDIUM
GHSA-q2qq-hmj6-3wpp
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
Details
During message encoding, `hickory-proto`'s `BinEncoder` stores pointers to labels that are candidates for name compression in a `Vec<(usize, Vec<u8>)>`. The name compression logic then searches for matches with a linear scan.
A malicious message with many records can both introduce many candidate labels, and invoke this linear scan many times. This can amplify CPU exhaustion in DoS attacks.
This is similar to [CVE-2024-8508](https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt).
### Reporter
Qifan Zhang, Palo Alto Networks
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/hickory-proto
Introduced in:
0.3.1Fixed in: 0.26.1Upgrade hickory-proto to 0.26.1 or newer (ecosystem crates.io).