hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
When the `hickory-resolver` name server pool implementation receives an upstream response with the TC (truncated) header bit set, it re-queues the request to the same nameserver to retry with UDP transport disabled. However, the retry arm never inspects the transport that just answered and carries no iteration counter. An authoritative server that sets `TC=1` on **every** available transport keeps the resolver spinning on one persistent TCP connection until the 5s per-request wall-clock deadline expires. ### Reporter Qifan Zhang, Palo Alto Networks
Recommended action
Recommended action
Upgrade affected packages to a patched version: hickory-resolver 0.26.2.
Technical details
- Vendor
- Not specified
- Product
- hickory-resolver
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source