Resource exhaustion in CoreDNS - CVE-2025-47950
Published: June 6, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the DNS-over-QUIC (DoQ) server implementation in server_quic.go. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Submariner
Netcool Operations Insight
openEuler
coredns
coredns-help
Storage Protect Server
How to mitigate CVE-2025-47950
Netcool Operations Insight - update to 1.6.15
coredns - addressed in versions 1.7.0-1.4, 1.7.0-1.6
coredns-help - addressed in versions 1.7.0-1.4, 1.7.0-1.6
Storage Protect Server - update to 8.1.27.100
External References
Related Security Bulletins
- Remote denial of service in CoreDNS DNS-over-QUIC
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in Netcool Operations Insight
- IBM Storage Protect Server update for Golang coredns library
- openEuler 24.03 LTS SP3 update for coredns
- openEuler 24.03 LTS SP1 update for coredns
- openEuler 22.03 LTS SP4 update for coredns
- openEuler 20.03 LTS SP4 update for coredns
- openEuler 24.03 LTS SP4 update for coredns