Intel

AIKIDO-2026-191928

hickory-proto is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-67wc-6jq8-ghrc Published 3 days ago

50

Medium Risk

This Affects:

RUSThickory-proto
0.24.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

The DNS wire-format parser pre-allocates record vectors from the ANCOUNT, NSCOUNT, and ARCOUNT header fields before reading the record data. A single datagram that sets these counts to their maximum forces large allocations even though parsing then fails. In client and resolver mode this path is reachable via spoofed responses, causing remote memory amplification. The fix avoids trusting the declared counts for pre-allocation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hickory-proto is vulnerable to Denial of Service (DoS) in versions 0.24.0 - 0.26.1.

How to fix this

Upgrade the hickory-proto library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform