VDB
Sign up
MEDIUM

GHSA-q2qq-hmj6-3wpp

hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression

Details

During message encoding, `hickory-proto`'s `BinEncoder` stores pointers to labels that are candidates for name compression in a `Vec<(usize, Vec<u8>)>`. The name compression logic then searches for matches with a linear scan.

A malicious message with many records can both introduce many candidate labels, and invoke this linear scan many times. This can amplify CPU exhaustion in DoS attacks.

This is similar to [CVE-2024-8508](https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt).

### Reporter

Qifan Zhang, Palo Alto Networks

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/hickory-proto
Introduced in: 0.3.1Fixed in: 0.26.1

Upgrade hickory-proto to 0.26.1 or newer (ecosystem crates.io).

References