Improper resource allocation In ruby-33
Description
A flaw was found in the resolv gem. An attacker controlling DNS responses (e.g., a spoofed response or a malicious upstream DNS server) can exploit this by sending crafted DNS responses containing many distinct unknown DNS resource record pairs or SvcParamKeys. This leads to uncontrolled memory growth, as each unknown entry generates a new class that is permanently registered and never reclaimed. Repeated exploitation can result in a Denial of Service (DoS) due to unbounded memory accumulation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
rpm rhel10 | |
rpm rhel6 | |
rpm rhel7 | |
rpm rhel8 | |
rpm rhel9 | |
rpm rhel9 | |
rpm rhel10 | |
rpm rhel8 | |
rpm rhel9 | |
rpm rhel10 |
1-10 of 12
10
Aliases