CVE-2026-35406
Impact
A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU.
Patches
https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1
Workarounds
None
Credits
Thanks to @dkane01 for reporting this
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/containers/aardvark-dns/security/advisories/GHSA-hfpq-x728-986j, https://nvd.nist.gov/vuln/detail/CVE-2026-35406, https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1, https://github.com/containers/aardvark-dns, https://github.com/containers/aardvark-dns/releases/tag/v1.17.1
