highVulnerability

GHSA-6w6g-hm98-mhgm

When the `hickory-resolver` name server pool implementation receives an upstream response with the TC (truncated) header bit set, it re-queues the request to the same nameserver to retry with UDP transport disabled. However, the retry arm never inspects the transport that just answered and carries no iteration counter. An authoritative server that sets `TC=1` on **every** available transport keeps the resolver spinning on one persistent TCP connection until the 5s per-request wall-clock deadline expires. ### Reporter Qifan Zhang, Palo Alto Networks

Properties

ghsa_id
GHSA-6w6g-hm98-mhgm
summary
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
severity
high
last_source
GitHub Advisory Database
cve_id
GHSA-6w6g-hm98-mhgm
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
true
retrieved_at
2026-10-06T03:05:59+00:00
ghsa_published
2026-10-05T22:55:10Z
source_url
https://github.com/advisories/GHSA-6w6g-hm98-mhgm
ghsa_updated
2026-10-05T22:55:12Z

Related Entities (6)

HAS_WEAKNESS (3)

→[Weakness]Loop with Unreachable Exit Condition ('Infinite Loop')
→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Insufficient Control of Network Message Volume (Network Amplification)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]rust/hickory-resolver

AFFECTS (1)

→[Software]rust/hickory-resolver

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-6w6g-hm98-mhgm — Ninja Signal Threat Intelligence | Ninja Signal