CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
Published Jun 6, 2025
7.5
HIGHCVSS 3.1
EPSS 1.19%
Description
CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream without imposing any limits on the number of concurrent streams or goroutines. A remote, unauthenticated attacker could open a large number of streams, leading to uncontrolled memory consumption and eventually causing an Out Of Memory (OOM) crash — especially in containerized or memory-constrained environments. The patch in version 1.12.2 introduces two key mitigation mechanisms: `max_streams`, which caps the number of concurrent QUIC streams per connection with a default value of `256`; and `worker_pool_size`, which Introduces a server-wide, bounded worker pool to process incoming streams with a default value of `1024`. This eliminates the 1:1 stream-to-goroutine model and ensures that CoreDNS remains resilient under high concurrency. Some workarounds are available for those who are unable to upgrade. Disable QUIC support by removing or commenting out the `quic://` block in the Corefile, use container runtime resource limits to detect and isolate excessive memory usage, and/or monitor QUIC connection patterns and alert on anomalies.
Affected products
-
Affected
- < 1.12.2
- < 1.12.2
No data.
Red Hat Advanced Cluster Management for Kubernetes 2.13
rhacm2/lighthouse-agent-rhel9:1782924920
Fixed · RHSA-2026:36873
Red Hat Advanced Cluster Management for Kubernetes 2.13
rhacm2/lighthouse-coredns-rhel9:1782924937
Fixed · RHSA-2026:36873
Red Hat Advanced Cluster Management for Kubernetes 2.13
rhacm2/lighthouse-coredns-rhel9:v0.20.2-1759168533
Fixed · RHSA-2025:17128
Red Hat Advanced Cluster Management for Kubernetes 2.14
rhacm2/lighthouse-agent-rhel9:v0.21-1762794425
Fixed · RHSA-2025:21892
Red Hat Advanced Cluster Management for Kubernetes 2.14
rhacm2/lighthouse-coredns-rhel9:v0.21-1762794442
Fixed · RHSA-2025:21892
Red Hat OpenShift Container Platform 4
openshift4/ose-coredns
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-coredns-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2.13 | rhacm2/lighthouse-agent-rhel9:1782924920 | Fixed | RHSA-2026:36873 |
| Red Hat Advanced Cluster Management for Kubernetes 2.13 | rhacm2/lighthouse-coredns-rhel9:1782924937 | Fixed | RHSA-2026:36873 |
| Red Hat Advanced Cluster Management for Kubernetes 2.13 | rhacm2/lighthouse-coredns-rhel9:v0.20.2-1759168533 | Fixed | RHSA-2025:17128 |
| Red Hat Advanced Cluster Management for Kubernetes 2.14 | rhacm2/lighthouse-agent-rhel9:v0.21-1762794425 | Fixed | RHSA-2025:21892 |
| Red Hat Advanced Cluster Management for Kubernetes 2.14 | rhacm2/lighthouse-coredns-rhel9:v0.21-1762794442 | Fixed | RHSA-2025:21892 |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-coredns | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-coredns-rhel9 | Not affected | n/a |
github.com/coredns/coredns
Go
Introduced 0 Fixed 1.12.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/coredns/coredns | 0 | 1.12.2 |
Remediation
Red Hat statement
On a Red Hat system, a denial of service to the CoreDNS service will not take down the host system, so the availability impact is assessed as Low for Red Hat systems.
Red Hat mitigation
Users unable to upgrade should manually disable the QUIC protocol support.
References (11)
- https://access.redhat.com/security/cve/CVE-2025-47950 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2370860 Issue Tracking
- https://datatracker.ietf.org/doc/html/rfc9250 x_refsource_MISCTechnical Description
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-17359 Advisory
- https://github.com/advisories/GHSA-cvx7-x8pj-x2gw Advisory
- https://github.com/coredns/coredns/commit/efaed02c6a480ec147b1f799aab7cf815b17dfe1 x_refsource_MISCPatch
- https://github.com/coredns/coredns/security/advisories/GHSA-cvx7-x8pj-x2gw x_refsource_CONFIRMVendor Advisory
- https://github.com/quic-go/quic-go x_refsource_MISCNot Applicable
- https://nvd.nist.gov/vuln/detail/CVE-2025-47950
- https://www.cve.org/CVERecord?id=CVE-2025-47950
- https://www.usenix.org/conference/usenixsecurity23/presentation/botella x_refsource_MISCBroken Link
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-47950 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2370860 | Issue Tracking | |
| https://datatracker.ietf.org/doc/html/rfc9250 | x_refsource_MISCTechnical Description | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-17359 | Advisory | |
| https://github.com/advisories/GHSA-cvx7-x8pj-x2gw | Advisory | |
| https://github.com/coredns/coredns/commit/efaed02c6a480ec147b1f799aab7cf815b17dfe1 | x_refsource_MISCPatch | |
| https://github.com/coredns/coredns/security/advisories/GHSA-cvx7-x8pj-x2gw | x_refsource_CONFIRMVendor Advisory | |
| https://github.com/quic-go/quic-go | x_refsource_MISCNot Applicable | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-47950 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-47950 | ||
| https://www.usenix.org/conference/usenixsecurity23/presentation/botella | x_refsource_MISCBroken Link |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub