CVE-2024-24788
Moderate
CVE-2024-24788
A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
Exploit probability
1.0%
Published
May 8, 2024
Required by
Not available
Last source change
April 16, 2026
02 / AFFECTED SOFTWARE
Affected packages
12 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2024-24788
View original source
A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
Open Source Vulnerabilities
GO-2024-2824
View original source
A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
Open Source Vulnerabilities
BIT-golang-2024-24788
View original source
A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2024/05/08/3
- https://go.dev/cl/578375
- https://go.dev/issue/66754
- https://groups.google.com/g/golang-announce/c/wkkO4P9stm0
- https://pkg.go.dev/vuln/GO-2024-2824
- https://security-tracker.debian.org/tracker/CVE-2024-24788
- https://security.netapp.com/advisory/ntap-20240605-0002/
- https://security.netapp.com/advisory/ntap-20240614-0001/
- https://nvd.nist.gov/vuln/detail/CVE-2024-24788