Vulnerability Description
The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/
- https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/
FAQ
What is CVE-2025-24294?
CVE-2025-24294 is a vulnerability with a CVSS score of 7.5 (HIGH). The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft...
How severe is CVE-2025-24294?
CVE-2025-24294 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24294?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.