CVE-2026-35406

HIGH7.5EPSS 0.01%

netavark has incorrect error handling for malformed tcp packets

Published: 4/7/2026Modified: 4/24/2026
Also known as:GHSA-hfpq-x728-986j

Description

### Impact A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. ### Patches https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1 ### Workarounds None ### Credits Thanks to @dkane01 for reporting this

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)