The vendor explicitly identifies these products as affected by this CVE.
- aardvark-dns.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8
- aardvark-dns (container-tools:rhel8) as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in aardvark-dns where a specially crafted TCP DNS query followed by a connection reset can trigger an infinite error loop, leading to 100% CPU usage and a denial of service. As aardvark-dns is only accessible via internal Podman networks, this issue can be exploited by a local container with network access.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
