<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aenaleantuleapcommunity/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:46:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aenaleantuleapcommunity/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Resource Exhaustion in hickory-resolver via Unbounded TC-Retry Loop</title><link>https://feed.craftedsignal.io/briefs/2026-10-hickory-resolver-dos/</link><pubDate>Tue, 06 Oct 2026 00:46:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hickory-resolver-dos/</guid><description>The hickory-resolver DNS library is vulnerable to a denial-of-service condition (CVE-2025-27150) where a malicious authoritative nameserver can induce an infinite retry loop by returning truncated responses.</description><content:encoded><![CDATA[<p>The <code>hickory-resolver</code> library, a popular DNS resolver implementation in Rust, contains a logic flaw within the <code>NameServerPool::try_send</code> function that allows for resource exhaustion. When the resolver receives a DNS response with the TC (truncated) flag set, it is programmed to retry the request using a different transport mechanism. However, the implementation fails to verify the transport state that previously provided the response and lacks a retry counter. Consequently, if a malicious authoritative nameserver sends a constant stream of responses with the <code>TC=1</code> bit set, the resolver enters an infinite loop, attempting to retry the request until the 5-second wall-clock deadline expires. This behavior leads to CPU and network resource exhaustion, effectively preventing the resolver from processing legitimate DNS queries for the duration of the timeout.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a Denial-of-Service (DoS) condition for applications relying on the <code>hickory-resolver</code> crate for DNS resolution. The vulnerability is highly relevant for network services, proxies, and infrastructure components that perform frequent outbound DNS queries, as attackers operating malicious authoritative nameservers can cause significant resolution latency or service outages.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>hickory-resolver</code> crate to version 0.26.2 or later to include the mandatory retry counter and transport validation logic.</li>
<li>Review network infrastructure logs for abnormal spikes in UDP/TCP traffic originating from external DNS nameservers associated with high latency or timeout errors.</li>
<li>Audit services utilizing versions 0.26.0-beta.1 through 0.26.1 for increased CPU usage or unresponsive DNS resolution threads.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>dns</category><category>rust</category><category>cve-2025-27150</category></item></channel></rss>