An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 12, 2018 |
| Debian | — | Upgrade haproxy | Jun 1, 2022 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade haproxy | Jun 27, 2019 | Dec 12, 2018 |
| Redhat Openshift | — | Upgrade openshift-enterprise-autohealUpgrade atomic-openshift-deschedulerUpgrade golang-github-prometheus-prometheusUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-openshift-web-consoleUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-cluster-autoscalerUpgrade jenkinsUpgrade openshift-enterprise-cluster-capacityUpgrade haproxyUpgrade atomic-openshiftUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshift-dockerregistryUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-service-idlerUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-metrics-serverUpgrade openshift-ansibleUpgrade jenkins-2-plugins | Mar 15, 2019 | Dec 12, 2018 |
| Suse | — | Upgrade haproxy | Jan 13, 2019 | Dec 12, 2018 |
| Ubuntu | — | Upgrade haproxy | Jan 23, 2019 | Dec 12, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub