Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hfpq-x728-986j netavark has incorrect error handling for malformed tcp packets
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 07 Apr 2026 22:00:00 +0000

Type Values Removed Values Added
Description Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
Title Aardvark-dns has incorrect error handling for malformed tcp packets
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-07T21:32:23.512Z

Reserved: 2026-04-02T17:03:42.075Z

Link: CVE-2026-35406

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-07T22:16:23.277

Modified: 2026-04-07T22:16:23.277

Link: CVE-2026-35406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses