An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 12, 2018 |
| Debian | — | Upgrade haproxy | Jun 1, 2022 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade haproxy | Jun 27, 2019 | Dec 12, 2018 |
| Redhat Openshift | — | Upgrade atomic-openshift-cluster-autoscalerUpgrade golang-github-prometheus-prometheusUpgrade openshift-enterprise-autohealUpgrade atomic-openshift-web-consoleUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-deschedulerUpgrade atomic-openshift-dockerregistryUpgrade golang-github-prometheus-alertmanagerUpgrade openshift-ansibleUpgrade atomic-openshift-metrics-serverUpgrade atomic-openshiftUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-service-idlerUpgrade openshift-enterprise-cluster-capacityUpgrade golang-github-openshift-oauth-proxyUpgrade jenkins-2-pluginsUpgrade haproxyUpgrade jenkins | Mar 15, 2019 | Dec 12, 2018 |
| Suse | — | Upgrade haproxy | Jan 13, 2019 | Dec 12, 2018 |
| Ubuntu | — | Upgrade haproxy | Jan 23, 2019 | Dec 12, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub