Impact
There is a vulnerability in GO managing malformed DNS message, which impacts Traefik.
This vulnerability could be exploited to cause a denial of service.
References
Patches
- https://github.com/traefik/traefik/releases/tag/v2.11.3
- https://github.com/traefik/traefik/releases/tag/v3.0.1
Workarounds
No workaround.
For more information
If you have any questions or comments about this advisory, please open an issue.
References:- https://github.com/traefik/traefik/security/advisories/GHSA-f7cq-5v43-8pwp
- https://github.com/advisories/GHSA-5fq7-4mxc-535h
- https://github.com/traefik/traefik/releases/tag/v2.11.3
- https://github.com/traefik/traefik/releases/tag/v3.0.1
- https://www.cve.org/CVERecord?id=CVE-2024-24788
- https://github.com/advisories/GHSA-f7cq-5v43-8pwp