Vulnerability record · CVE-2024-8418 · published 4 September 2024
CVE-2024-8418: Containers aardvark-dns uncontrolled resource consumption vulnerability
Containers · Aardvark Dns
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.
Description
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2025:7094 | |
| https://access.redhat.com/security/cve/CVE-2024-8418 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2309683 | Issue Tracking |
| https://github.com/containers/aardvark-dns/issues/500 | ExploitIssue Tracking |
| https://github.com/containers/aardvark-dns/pull/503 | Issue Tracking |
Track CVE-2024-8418 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8418), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.