CVE-2016-2224

high
Published 2017-03-24 ยท Modified 2026-05-13
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.5

Description

The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply.

Predictions

Exploit likelihood
83%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2016-2224 NameCVE-2016-2224 DescriptionThe __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search,โ€ฆ

CVE-2016-2224

NameCVE-2016-2224
DescriptionThe __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-561-1
Debian Bugs990648

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
uclibc (PTS)bookworm, bullseye, trixie1.0.35-1fixed
forky, sid1.0.54-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
uclibcsourcewheezy0.9.32-1+deb7u1DLA-561-1
uclibcsource(unstable)1.0.20-1unimportant990648

Notes

Just for cross-compiling, not used for actual packages
https://repo.or.cz/uclibc-ng.git/commit/d9c3a16dcab57d6b56225b9a67e9119cc9e2e4ac
https://www.openwall.com/lists/oss-security/2016/02/05/2

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
Just for cross-compiling, not used for actual packageshttps://repo.or.cz/uclibc-ng.git/commit/d9c3a16dcab57d6b56225b9a67e9119cc9e2e4achttps://www.openwall.com/lists/oss-security/2016/02/05/2

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.0.20-1
debian debianbullseyefixed1.0.20-1
debian debianforkyfixed1.0.20-1
debian debiansidfixed1.0.20-1
debian debiantrixiefixed1.0.20-1

Application impact

VendorProductVersionsFixed
uclibc-ng_projectuclibc-ng{"endIncluding":"1.0.11"}

References

CWEs

CWE-400

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.