{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2025-27150/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*","cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2025-27150"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["hickory-resolver (\u003e= 0.26.0-beta.1, \u003c 0.26.2)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","dns","rust","cve-2025-27150"],"_cs_type":"advisory","_cs_vendors":["Hickory DNS"],"content_html":"\u003cp\u003eThe \u003ccode\u003ehickory-resolver\u003c/code\u003e library, a popular DNS resolver implementation in Rust, contains a logic flaw within the \u003ccode\u003eNameServerPool::try_send\u003c/code\u003e function that allows for resource exhaustion. When the resolver receives a DNS response with the TC (truncated) flag set, it is programmed to retry the request using a different transport mechanism. However, the implementation fails to verify the transport state that previously provided the response and lacks a retry counter. Consequently, if a malicious authoritative nameserver sends a constant stream of responses with the \u003ccode\u003eTC=1\u003c/code\u003e bit set, the resolver enters an infinite loop, attempting to retry the request until the 5-second wall-clock deadline expires. This behavior leads to CPU and network resource exhaustion, effectively preventing the resolver from processing legitimate DNS queries for the duration of the timeout.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a Denial-of-Service (DoS) condition for applications relying on the \u003ccode\u003ehickory-resolver\u003c/code\u003e crate for DNS resolution. The vulnerability is highly relevant for network services, proxies, and infrastructure components that perform frequent outbound DNS queries, as attackers operating malicious authoritative nameservers can cause significant resolution latency or service outages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003ehickory-resolver\u003c/code\u003e crate to version 0.26.2 or later to include the mandatory retry counter and transport validation logic.\u003c/li\u003e\n\u003cli\u003eReview network infrastructure logs for abnormal spikes in UDP/TCP traffic originating from external DNS nameservers associated with high latency or timeout errors.\u003c/li\u003e\n\u003cli\u003eAudit services utilizing versions 0.26.0-beta.1 through 0.26.1 for increased CPU usage or unresponsive DNS resolution threads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:46:18Z","date_published":"2026-10-06T00:46:18Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hickory-resolver-dos/","summary":"The hickory-resolver DNS library is vulnerable to a denial-of-service condition (CVE-2025-27150) where a malicious authoritative nameserver can induce an infinite retry loop by returning truncated responses.","title":"Resource Exhaustion in hickory-resolver via Unbounded TC-Retry Loop","url":"https://feed.craftedsignal.io/briefs/2026-10-hickory-resolver-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2025-27150","version":"https://jsonfeed.org/version/1.1"}